traceroute-circl by CIRCL

Traceroute improved wrapper for CSIRT and CERT operators

updated at Aug. 6, 2021, 6:54 p.m.

Unknown languages

16 +0

36 +0

9 +0

GitHub
Panorama by AlmCo

Fast incident overview

updated at Jan. 2, 2023, 1:12 a.m.

Python

3 +0

38 +0

6 +0

GitHub
pyarascanner by nogoodconfig

A simple many-rules to many-files YARA scanner for incident response or malware zoos.

updated at July 6, 2023, 2:10 a.m.

Python

3 +0

25 +0

4 +0

GitHub
PowerGRR by swisscom

PowerGRR is an API client library in PowerShell working on Windows, Linux and macOS for GRR automation and scripting.

updated at Aug. 26, 2023, 6:23 p.m.

PowerShell

20 +0

56 +0

7 +0

GitHub
cuckoo-modified-api by keithjjones

A Python library to interface with a cuckoo-modified instance

updated at Dec. 4, 2023, 6:09 p.m.

Python

6 +0

18 +0

7 +0

GitHub
visualize_logs by keithjjones

A Python library and command line tools to provide interactive log visualization.

updated at Dec. 26, 2023, 12:22 p.m.

HTML

15 +0

134 +0

36 +0

GitHub
sqhunter by 0x4D31

A simple threat hunting tool based on osquery, Salt Open and Cymon API

updated at Jan. 3, 2024, 2:14 p.m.

Python

12 +0

65 +0

15 +0

GitHub
domfind by diogo-fernan

A Python DNS crawler to find identical domain names under different TLDs.

updated at Jan. 4, 2024, 12:28 p.m.

Python

4 +0

20 +0

3 +0

GitHub
IRTriage by AJMartel

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

updated at Jan. 21, 2024, 3:33 p.m.

AutoIt

17 +0

123 +0

26 +0

GitHub
Fastir_Collector_Linux by SekoiaLab

None

updated at Jan. 25, 2024, 4:16 p.m.

Python

23 +0

165 +0

42 +0

GitHub
PowerSponse by swisscom

PowerSponse is a PowerShell module focused on targeted containment and remediation during incident response.

updated at Jan. 29, 2024, 5:35 p.m.

PowerShell

15 +0

36 +0

6 +0

GitHub
CIRTKit by opensourcesec

Tools for the Computer Incident Response Team computer

updated at Jan. 31, 2024, 10:04 a.m.

Python

19 +0

140 +0

25 +0

GitHub
lorg by jensvoid

Apache Logfile Security Analyzer

updated at Jan. 31, 2024, 10:42 a.m.

HTML

42 +0

207 +0

50 +0

GitHub
inVtero.net by ShaneK2

inVtero.net: A high speed (Gbps) Forensics, Memory integrity & assurance. Includes offensive & defensive memory capabilities. Find/Extract processes, hypervisors (including nested) in memory dumps using microarchitechture independent Virtual Machiene Introspection techniques

updated at Feb. 5, 2024, 5:10 p.m.

C#

31 +0

276 +0

57 +0

GitHub
hostintel by keithjjones

A modular Python application to collect intelligence for malicious hosts.

updated at Feb. 9, 2024, 5:33 p.m.

Python

30 +0

258 +0

52 +0

GitHub
falcon-orchestrator by CrowdStrike

CrowdStrike Falcon Orchestrator provides automated workflow and response capabilities

updated at Feb. 9, 2024, 8:47 p.m.

JavaScript

36 +0

183 +0

60 +0

GitHub
imagemounter by ralphje

Command line utility and Python package to ease the (un)mounting of forensic disk images

updated at March 1, 2024, 8:14 a.m.

Python

13 +0

111 +0

36 +0

GitHub
morgue by etsy

post mortem tracker

updated at March 6, 2024, 10:03 p.m.

PHP

75 +0

1,011 +0

133 +0

GitHub
AutoTTP by jymcheong

Automated Tactics Techniques & Procedures

updated at March 8, 2024, 11:16 a.m.

Python

24 +0

244 +0

64 +0

GitHub
doorman by mwielgoszewski

an osquery fleet manager

updated at March 8, 2024, 11:26 a.m.

Python

33 +0

616 +0

95 +0

GitHub