Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders
created at June 9, 2020, 12:12 p.m.
WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)
created at May 13, 2021, 10:33 p.m.
Zentral is a high-visibility platform for controlling Apple endpoints in enterprises. It brings great observability to IT and makes tracking & reporting compliance much less manual.
created at Oct. 20, 2015, 2:03 p.m.
A machine learning tool that ranks strings based on their relevance for malware analysis.
created at Sept. 5, 2019, 1:02 p.m.
CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.
created at Jan. 30, 2016, 4:58 a.m.
(DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR) teams quickly identify suspicious hosts on which to focus their response.
created at May 1, 2018, 10:11 p.m.
Incident Response Forensic Framework
created at July 6, 2016, 11:02 a.m.
Collection of Event ID ressources useful for Digital Forensics and Incident Response
created at Sept. 22, 2021, 3:36 p.m.
Volatility plugin for extracts configuration data of known malware
created at April 22, 2019, 12:23 a.m.