Back to Topics Directory
Topic Hub

#dfir (26 Repositories)

Ranked open-source repositories tagged with #dfir, scored by pull request acceptance likelihood and maintainer engagement velocity.

Topic Avg Merge Rate

20.5%

Avg Review Latency

14.5h

Filter by language

26 repositories tagged #dfir

S TierRust 196

Yamato-Security/suzaku

Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.

95.7%
Merge Rate
4h
First Review
100%
1st-Timers
4
Maintainers
A TierKotlin 188

BARGHEST-ngo/MESH

Wireless ADB, over the internet; not just local Wi-Fi. An encrypted, censorship-resistant mesh VPN making remote forensics and network monitoring seamless.

91.1%
Merge Rate
22h
First Review
100%
1st-Timers
3
Maintainers
A TierC++ 7.9k 5 GFIs

zeek/zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

82.6%
Merge Rate
3d
First Review
68%
1st-Timers
22
Maintainers
B TierJavaScript 345

r3nzsec/irflow-timeline

DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt, process inspection, lateral movement tracking, persistence detection, and VirusTotal enrichment.

100.0%
Merge Rate
-
First Review
100%
1st-Timers
0
Maintainers
B TierPython 648

MISP/misp-warninglists

Warning lists to inform users of MISP about potential false-positives or other information in indicators

40.0%
Merge Rate
3h
First Review
50%
1st-Timers
2
Maintainers
B TierRust 373

mandiant/macos-UnifiedLogs

A cross platform parser for Apple UnifiedLogs!

100.0%
Merge Rate
10h
First Review
0%
1st-Timers
1
Maintainers
C TierRust 348

Neo23x0/Loki-RS

🐍 High-performance, multi-threaded YARA & IOC scanner

23.8%
Merge Rate
4d
First Review
0%
1st-Timers
1
Maintainers
D TierMulti-language 5.2k

cugu/awesome-forensics

⭐️ A curated list of awesome forensic analysis tools and resources

0.0%
Merge Rate
2d
First Review
0%
1st-Timers
1
Maintainers
D TierPython 1.5k

RyanDFIR/hindsight

Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierScala 1.6k

TheHive-Project/Cortex

Cortex: a Powerful Observable Analysis and Active Response Engine

0.0%
Merge Rate
6d
First Review
0%
1st-Timers
1
Maintainers
D TierPOPowerShell 202

kacos2000/Win10

Win 10/11 related research

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 222

Yamato-Security/hayabusa-rules

Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierC++ 447

DFIR-ORC/dfir-orc

Forensics artefact collection tool for systems running Microsoft Windows

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 282

ANSSI-FR/DFIR-O365RC

PowerShell module for Office 365 and Azure log collection

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 265

LETHAL-FORENSICS/Collect-MemoryDump

Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 357

olafhartong/ATTACKdatamap

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 793

google/turbinia

Automation and Scaling of Digital Forensics Tools

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierJavaScript 188

cgosec/Blauhaunt

A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 257

kfallahi/UnderlayCopy

PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierXSXSLT 8.8k

LOLBAS-Project/LOLBAS

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierShell 9.5k

toniblyx/my-arsenal-of-aws-security-tools

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierMulti-language 9.4k

meirwah/awesome-incident-response

A curated list of tools for incident response

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 340

joeavanzato/Trawler

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierC++ 332

BSI-Bund/RdpCacheStitcher

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 4.6k

OTRF/ThreatHunter-Playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 103

helixmap/sigwood

Local-first, transparent threat hunting for the logs you already have: Zeek, Pi-hole, syslog, CloudTrail. Named technique behind every finding. No SIEM, no agent, no black box.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
Best Dfir Open Source Repositories & C-Rank™ | GetMerged