Yara EndpointYara-Endpoint is a tool useful for incident response as well as anti-malware enpoint base on Yara signatures.
Stars: ✭ 75 (-86.61%)
PypowershellxrayPython script to decode common encoded PowerShell scripts
Stars: ✭ 192 (-65.71%)
IntelowlIntel Owl: analyze files, domains, IPs in multiple ways from a single API at scale
Stars: ✭ 2,114 (+277.5%)
Wazuh DockerWazuh - Docker containers
Stars: ✭ 213 (-61.96%)
ThreathuntThreatHunt is a PowerShell repository that allows you to train your threat hunting skills.
Stars: ✭ 92 (-83.57%)
assisted-log-enabler-for-awsAssisted Log Enabler for AWS - Find AWS resources that are not logging, and turn them on.
Stars: ✭ 167 (-70.18%)
HistoricprocesstreeAn Incident Response tool that visualizes historic process execution evidence (based on Event ID 4688 - Process Creation Event) in a tree view.
Stars: ✭ 46 (-91.79%)
WefflesBuild a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI
Stars: ✭ 176 (-68.57%)
OrianaOriana is a threat hunting tool that leverages a subset of Windows events to build relationships, calculate totals and run analytics. The results are presented in a Web layer to help defenders identify outliers and suspicious behavior on corporate environments.
Stars: ✭ 152 (-72.86%)
BashfuscatorA fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
Stars: ✭ 690 (+23.21%)
Atc ReactA knowledge base of actionable Incident Response techniques
Stars: ✭ 226 (-59.64%)
Edr Testing ScriptTest the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-CradleCrafter/Invoke-DOSfuscation payloads
Stars: ✭ 136 (-75.71%)
PowerSponsePowerSponse is a PowerShell module focused on targeted containment and remediation during incident response.
Stars: ✭ 35 (-93.75%)
PatrowldocsPatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform
Stars: ✭ 105 (-81.25%)
Dfir OrcForensics artefact collection tool for systems running Microsoft Windows
Stars: ✭ 202 (-63.93%)
ResponseMonzo's real-time incident response and reporting tool ⚡️
Stars: ✭ 1,252 (+123.57%)
macOS-irPrototype to collect data and analyse it from a compromised macOS device.
Stars: ✭ 16 (-97.14%)
WazuhWazuh - The Open Source Security Platform
Stars: ✭ 3,154 (+463.21%)
Analyst CasefileMaltego CaseFile entities for information security investigations, malware analysis and incident response
Stars: ✭ 41 (-92.68%)
Cortex4pyPython API Client for Cortex
Stars: ✭ 22 (-96.07%)
Aurora Incident ResponseIncident Response Documentation made easy. Developed by Incident Responders for Incident Responders
Stars: ✭ 171 (-69.46%)
PatrowlenginesPatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform
Stars: ✭ 162 (-71.07%)
Vast🔮 Visibility Across Space and Time
Stars: ✭ 227 (-59.46%)
SleuthkitThe Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
Stars: ✭ 1,948 (+247.86%)
PackratLive system forensic collector
Stars: ✭ 16 (-97.14%)
Thehive4pyPython API Client for TheHive
Stars: ✭ 143 (-74.46%)
MthcAll-in-one bundle of MISP, TheHive and Cortex
Stars: ✭ 134 (-76.07%)
RdpCacheStitcherRdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
Stars: ✭ 176 (-68.57%)
Information Security TasksThis repository is created only for infosec professionals whom work day to day basis to equip ourself with uptodate skillset, We can daily contribute daily one hour for day to day tasks and work on problem statements daily, Please contribute by providing problem statements and solutions
Stars: ✭ 108 (-80.71%)
ScotSandia Cyber Omni Tracker (SCOT)
Stars: ✭ 206 (-63.21%)
SiacSIAC is an enterprise SIEM built on open-source technology.
Stars: ✭ 100 (-82.14%)
CCXDiggerThe CyberCX Digger project is designed to help Australian organisations determine if they have been impacted by certain high profile cyber security incidents. Digger provides threat hunting functionality packaged in a simple-to-use tool, allowing users to detect certain attacker activities; all for free.
Stars: ✭ 45 (-91.96%)
AwesomeA curated list of awesome things related to TheHive & Cortex
Stars: ✭ 88 (-84.29%)
PockintA portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️
Stars: ✭ 196 (-65%)
ThePhishThePhish: an automated phishing email analysis tool
Stars: ✭ 676 (+20.71%)
Ioc ExplorerExplore Indicators of Compromise Automatically
Stars: ✭ 73 (-86.96%)
Litmus testDetecting ATT&CK techniques & tactics for Linux
Stars: ✭ 190 (-66.07%)
ScriptingPS / Bash / Python / Other scripts For FUN!
Stars: ✭ 47 (-91.61%)
evtx-hunterevtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.
Stars: ✭ 122 (-78.21%)
Ios Triageincident response tool for iOS devices
Stars: ✭ 42 (-92.5%)
OsctrlFast and efficient osquery management
Stars: ✭ 183 (-67.32%)
BeagleBeagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
Stars: ✭ 976 (+74.29%)
yara-exporterExporting MISP event attributes to yara rules usable with Thor apt scanner
Stars: ✭ 22 (-96.07%)
Wazuh ChefWazuh - Chef cookbooks
Stars: ✭ 9 (-98.39%)
Imago ForensicsImago is a python tool that extract digital evidences from images.
Stars: ✭ 175 (-68.75%)
Awesome SreA curated list of Site Reliability and Production Engineering resources.
Stars: ✭ 7,687 (+1272.68%)
AsnASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation and geolocation lookup tool / Traceroute server
Stars: ✭ 242 (-56.79%)
Misp TaxonomiesTaxonomies used in MISP taxonomy system and can be used by other information sharing tool.
Stars: ✭ 168 (-70%)
MEATThis toolkit aims to help forensicators perform different kinds of acquisitions on iOS devices
Stars: ✭ 101 (-81.96%)
urlRecon📝 urlRecon - Info Gathering or Recon tool for Urls -> Retrieves * Whois information of the domain * DNS Details of the domain * Server Fingerprint * IP geolocation of the server
Stars: ✭ 31 (-94.46%)
pyarascannerA simple many-rules to many-files YARA scanner for incident response or malware zoos.
Stars: ✭ 23 (-95.89%)
DfirtrackDFIRTrack - The Incident Response Tracking Application
Stars: ✭ 232 (-58.57%)
ThehiveTheHive: a Scalable, Open Source and Free Security Incident Response Platform
Stars: ✭ 2,300 (+310.71%)