Incident Response
218 items from meirwah/awesome-incident-response ★9,443
-
-
-
Fibratus github.com
Fibratus is a tool for exploration and tracing of the Windows kernel. It is able to capture the most of the Windows kernel activity - process/thread creation and termination, file system I/O, registry, network activity, DLL loading/unloading and much more. Fibratus has a very…
-
-
Fleet device management github.com
Lightweight, programmable telemetry for servers and workstations.
-
grr github.com
GRR Rapid Response is an incident response framework focused on remote live forensics.
-
-
Atomic Red Team (ART) github.com
Small and highly portable detection tests mapped to the MITRE ATT&CK Framework.
-
-
-
stenographer github.com
Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets.
-
Matano github.com
Open source serverless security lake platform on AWS that lets you ingest, store, and analyze petabytes of security data into an Apache Iceberg data lake and run realtime Python detections as code.
-
CAPA github.com
detects capabilities in executable files. You run it against a PE, ELF, .NET module, or shellcode file and it tells you what it thinks the program can do.
-
-
-
-
-
LogonTracer github.com
Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.
-
-
-
APTSimulator github.com
Windows Batch script that uses a set of tools and output files to make a system look as if it was compromised.
-
MozDef github.com
Automates the security incident handling process and facilitate the real-time activities of incident handlers.
-
ir-rescue github.com
ir-rescue is a Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.
-
-
-
Caldera github.com
Automated adversary emulation system that performs post-compromise adversarial behavior within Windows Enterprise networks. It generates plans during operation using a planning system and a pre-configured adversary model based on the Adversarial Tactics, Techniques & Common…
-
Viper github.com
Python based binary analysis and management framework, that works well with Cuckoo and YARA.
-
-
bulk_extractor github.com
Computer forensics tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures. Because of ignoring the file system structure, the program distinguishes itself in terms of speed and…
-
- next page of items loading…