#dfir (26 Repositories)
Ranked open-source repositories tagged with #dfir, scored by pull request acceptance likelihood and maintainer engagement velocity.
20.5%
14.5h
26 repositories tagged #dfir
Yamato-Security/suzaku
Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.
BARGHEST-ngo/MESH
Wireless ADB, over the internet; not just local Wi-Fi. An encrypted, censorship-resistant mesh VPN making remote forensics and network monitoring seamless.
zeek/zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
r3nzsec/irflow-timeline
DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret Hunt, process inspection, lateral movement tracking, persistence detection, and VirusTotal enrichment.
MISP/misp-warninglists
Warning lists to inform users of MISP about potential false-positives or other information in indicators
mandiant/macos-UnifiedLogs
A cross platform parser for Apple UnifiedLogs!
Neo23x0/Loki-RS
🐍 High-performance, multi-threaded YARA & IOC scanner
cugu/awesome-forensics
⭐️ A curated list of awesome forensic analysis tools and resources
RyanDFIR/hindsight
Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox
TheHive-Project/Cortex
Cortex: a Powerful Observable Analysis and Active Response Engine
kacos2000/Win10
Win 10/11 related research
Yamato-Security/hayabusa-rules
Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.
DFIR-ORC/dfir-orc
Forensics artefact collection tool for systems running Microsoft Windows
ANSSI-FR/DFIR-O365RC
PowerShell module for Office 365 and Azure log collection
LETHAL-FORENSICS/Collect-MemoryDump
Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
olafhartong/ATTACKdatamap
A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework
google/turbinia
Automation and Scaling of Digital Forensics Tools
cgosec/Blauhaunt
A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts
kfallahi/UnderlayCopy
PowerShell toolkit that extracts locked Windows files (SAM, SYSTEM, NTDS, ...) using MFT parsing and raw disk reads
LOLBAS-Project/LOLBAS
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
toniblyx/my-arsenal-of-aws-security-tools
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
meirwah/awesome-incident-response
A curated list of tools for incident response
joeavanzato/Trawler
PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.
BSI-Bund/RdpCacheStitcher
RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
OTRF/ThreatHunter-Playbook
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
helixmap/sigwood
Local-first, transparent threat hunting for the logs you already have: Zeek, Pi-hole, syslog, CloudTrail. Named technique behind every finding. No SIEM, no agent, no black box.