dogear

enter for all results · esc to close

Incident Response

218 items from meirwah/awesome-incident-response ★9,443

  1. Volatility github.com

    Python based memory extraction and analysis framework.

  2. Ghidra github.com

    Software Reverse Engineering Framework.

  3. Fibratus github.com

    Fibratus is a tool for exploration and tracing of the Windows kernel. It is able to capture the most of the Windows kernel activity - process/thread creation and termination, file system I/O, registry, network activity, DLL loading/unloading and much more. Fibratus has a very…

  4. Flare VM github.com

    Based on Windows.

  5. Fleet device management github.com

    Lightweight, programmable telemetry for servers and workstations.

  6. grr github.com

    GRR Rapid Response is an incident response framework focused on remote live forensics.

  7. LOKI github.com

    Simple Indicators of Compromise and Incident Response Scanner

  8. Atomic Red Team (ART) github.com

    Small and highly portable detection tests mapped to the MITRE ATT&CK Framework.

  9. Sigma github.com

    Generic signature format for SIEM systems already containing an extensive ruleset.

  10. FIR github.com

    Fast Incident Response, a cybersecurity incident management platform.

  11. stenographer github.com

    Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets.

  12. Matano github.com

    Open source serverless security lake platform on AWS that lets you ingest, store, and analyze petabytes of security data into an Apache Iceberg data lake and run realtime Python detections as code.

  13. CAPA github.com

    detects capabilities in executable files. You run it against a PE, ELF, .NET module, or shellcode file and it tells you what it thinks the program can do.

  14. Radare2 github.com

    Reverse engineering framework and command-line toolset.

  15. Cutter github.com

    Free and Open Source Reverse Engineering Platform powered by rizin.

  16. HELK github.com

    Threat Hunting platform.

  17. Timesketch github.com

    Collaborative forensic timeline analysis.

  18. LogonTracer github.com

    Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.

  19. OSX Auditor github.com

    Free Mac OS X computer forensics tool.

  20. logdissect github.com

    CLI utility and Python API for analyzing log files and other data.

  21. APTSimulator github.com

    Windows Batch script that uses a set of tools and output files to make a system look as if it was compromised.

  22. MozDef github.com

    Automates the security incident handling process and facilitate the real-time activities of incident handlers.

  23. ir-rescue github.com

    ir-rescue is a Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

  24. LiME github.com

    Linux Memory Extractor

  25. OSX Collector github.com

    OSX Auditor offshoot for live response.

  26. Caldera github.com

    Automated adversary emulation system that performs post-compromise adversarial behavior within Windows Enterprise networks. It generates plans during operation using a planning system and a pre-configured adversary model based on the Adversarial Tactics, Techniques & Common…

  27. Viper github.com

    Python based binary analysis and management framework, that works well with Cuckoo and YARA.

  28. PowerForensics github.com

    Live disk forensics platform, using PowerShell.

  29. bulk_extractor github.com

    Computer forensics tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures. Because of ignoring the file system structure, the program distinguishes itself in terms of speed and…

  30. Cuckoo github.com

    Open Source Highly configurable sandboxing tool.

  31. next page of items loading…