AChoir by OMENScan

Windows Live Artifacts Acquisition Script

updated at May 5, 2024, 11:48 p.m.

C++

14 +0

176 +1

31 +0

GitHub
appcompatprocessor by mbevilacqua

"Evolving AppCompat/AmCache data analysis beyond grep"

updated at May 5, 2024, 5:56 p.m.

Python

17 +0

189 +1

26 +0

GitHub
mastiff by KoreLogicSecurity

Malware static analysis framework

updated at May 4, 2024, 9:59 p.m.

Python

18 +0

173 +0

39 +0

GitHub
security-onion by Security-Onion-Solutions

Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

updated at May 2, 2024, 10:25 a.m.

Unknown languages

302 +0

3,055 +0

518 +0

GitHub
rastrea2r by rastrea2r

Collecting & Hunting for IOCs with gusto and style

updated at May 2, 2024, 7:34 a.m.

Python

18 +0

234 +0

53 +0

GitHub
DumpsterFire by TryCatchHCF

"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.

updated at April 30, 2024, 7:23 p.m.

Python

50 +0

967 +0

148 +0

GitHub
CyLR by orlikoski

CyLR - Live Response Collection Tool

updated at April 30, 2024, 6:03 p.m.

C#

32 +0

600 +0

88 +0

GitHub
MozDef by mozilla

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

updated at April 30, 2024, 6:38 a.m.

Python

149 +0

2,173 +0

328 +0

GitHub
streamalert by airbnb

StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define.

updated at April 30, 2024, 3:04 a.m.

Python

101 +0

2,826 +0

334 +0

GitHub
osxcollector by Yelp

A forensic evidence collection & analysis toolkit for OS X

updated at April 29, 2024, 8:41 a.m.

Python

125 +0

1,861 +0

240 +0

GitHub
Skadi by orlikoski

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

updated at April 28, 2024, 12:33 a.m.

Shell

37 +0

479 +0

68 +0

GitHub
CimSweep by mattifestation

CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.

updated at April 28, 2024, 12:09 a.m.

PowerShell

75 +0

634 +0

150 +0

GitHub
OSXAuditor by jipegit

OS X Auditor is a free Mac OS X computer forensics tool

updated at April 27, 2024, 4:08 p.m.

JavaScript

183 +0

3,130 +0

282 +0

GitHub
diffy by Netflix-Skunkworks

no entry (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR) teams quickly identify suspicious hosts on which to focus their response.

updated at April 27, 2024, 8:50 a.m.

Python

143 +0

635 +0

60 +0

GitHub
metta by uber-common

An information security preparedness tool to do adversarial simulation.

updated at April 27, 2024, 8:50 a.m.

Python

74 +0

1,074 +0

151 +0

GitHub
margaritashotgun by ThreatResponse

Remote Memory Acquisition Tool

updated at April 27, 2024, 8:50 a.m.

Python

17 +0

235 +0

50 +0

GitHub
ir-rescue by diogo-fernan

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

updated at April 27, 2024, 8:50 a.m.

Batchfile

45 +0

447 +0

93 +0

GitHub
nightHawkResponse by biggiesmallsAG

Incident Response Forensic Framework

updated at April 27, 2024, 8:49 a.m.

Go

82 +0

596 +0

139 +0

GitHub
threat_note by DefensePointSecurity

DPS' Lightweight Investigation Notebook

updated at April 27, 2024, 8:49 a.m.

HTML

57 +0

420 +0

97 +0

GitHub
stenographer by google

Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com

updated at April 25, 2024, 6:46 p.m.

Go

104 +0

1,788 +0

232 +1

GitHub