-
ForensicMiner Public
Forked from securityjoes/ForensicMinerA really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.
PowerShell MIT License UpdatedFeb 22, 2025 -
Active_Directory_Advanced_Threat_Hunting Public
Forked from tomwechsler/Active_Directory_Advanced_Threat_HuntingThis repo is about Active Directory Advanced Threat Hunting
PowerShell UpdatedFeb 22, 2025 -
santa Public
Forked from google/santaA binary authorization and monitoring system for macOS
Objective-C++ Apache License 2.0 UpdatedFeb 22, 2025 -
hindsight Public
Forked from obsidianforensics/hindsightWeb browser forensics for Google Chrome/Chromium
Python Apache License 2.0 UpdatedFeb 22, 2025 -
timesketch Public
Forked from google/timesketchCollaborative forensic timeline analysis
Python Apache License 2.0 UpdatedFeb 22, 2025 -
Win11Debloat Public
Forked from Raphire/Win11DebloatA simple, easy to use powershell script to remove bloatware apps from windows, disable telemetry, bing in windows search aswell as perform various other changes to declutter and improve your window…
PowerShell MIT License UpdatedFeb 22, 2025 -
google-osdfir-infrastructure Public
Forked from google/osdfir-infrastructureHelm charts for running open source digital forensic tools in Kubernetes
Smarty Apache License 2.0 UpdatedFeb 22, 2025 -
Hunting-Queries-Detection-Rules Public
Forked from alexverboon/Hunting-Queries-Detection-RulesKQL Queries. Microsoft 365 Defender, Microsoft Sentinel
BSD 3-Clause "New" or "Revised" License UpdatedFeb 22, 2025 -
Misconfiguration-Manager Public
Forked from subat0mik/Misconfiguration-ManagerMisconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive and hardening guidance.
PowerShell GNU General Public License v3.0 UpdatedFeb 22, 2025 -
pacu Public
Forked from RhinoSecurityLabs/pacuThe AWS exploitation framework, designed for testing the security of Amazon Web Services environments.
Python BSD 3-Clause "New" or "Revised" License UpdatedFeb 22, 2025 -
ROADtools Public
Forked from dirkjanm/ROADtoolsA collection of Azure AD/Entra tools for offensive and defensive security purposes
Python MIT License UpdatedFeb 22, 2025 -
ThreatHunting-Keywords Public
Forked from mthcht/ThreatHunting-KeywordsAwesome list of keywords for Threat Hunting sessions
PowerShell UpdatedFeb 22, 2025 -
mac_apt Public
Forked from ydkhatri/mac_aptmacOS (& ios) Artifact Parsing Tool
Python MIT License UpdatedFeb 22, 2025 -
capa Public
Forked from mandiant/capaThe FLARE team's open-source tool to identify capabilities in executable files.
Python Apache License 2.0 UpdatedFeb 22, 2025 -
KQL-threat-hunting-queries Public
Forked from cyb3rmik3/KQL-threat-hunting-queriesA repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft 365 Defender.
MIT License UpdatedFeb 22, 2025 -
digital-forensics-lab Public
Forked from frankwxu/digital-forensics-labFree hands-on digital forensics labs for students and faculty
Jupyter Notebook Other UpdatedFeb 22, 2025 -
awesome-forensics Public
Forked from cugu/awesome-forensicsA curated list of awesome forensic analysis tools and resources
Creative Commons Zero v1.0 Universal UpdatedFeb 22, 2025 -
Sentinel-Queries Public
Forked from reprise99/Sentinel-QueriesCollection of KQL queries
MIT License UpdatedFeb 22, 2025 -
auditd Public
Forked from Neo23x0/auditdBest Practice Auditd Configuration
Apache License 2.0 UpdatedFeb 22, 2025 -
audit-userspace Public
Forked from linux-audit/audit-userspaceLinux audit userspace repository
C GNU General Public License v2.0 UpdatedFeb 22, 2025 -
chainsaw Public
Forked from WithSecureLabs/chainsawRapidly Search and Hunt through Windows Event Logs
Rust GNU General Public License v3.0 UpdatedFeb 22, 2025 -
SecLists Public
Forked from danielmiessler/SecListsSecLists is the security tester's companion. It's a collection of multiple types of lists used during security assessments, collected in one place. List types include usernames, passwords, URLs, se…
PHP MIT License UpdatedFeb 22, 2025 -
GOAD Public
Forked from Orange-Cyberdefense/GOADgame of active directory
PowerShell GNU General Public License v3.0 UpdatedFeb 22, 2025 -
MemProcFS Public
Forked from ufrisk/MemProcFSMemProcFS
C GNU Affero General Public License v3.0 UpdatedFeb 19, 2025 -
SysmonCommunityGuide Public
Forked from trustedsec/SysmonCommunityGuideTrustedSec Sysinternals Sysmon Community Guide
CSS UpdatedDec 4, 2024 -
APT-Hunter Public
Forked from ahmedkhlief/APT-HunterAPT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover su…
Python GNU General Public License v3.0 UpdatedDec 4, 2024 -
-
Azure-Red-Team Public
Forked from rootsecdev/Azure-Red-TeamAzure Security Resources and Notes
PowerShell UpdatedDec 4, 2024 -
Incident-Playbook Public
Forked from austinsonger/Incident-PlaybookGOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]
MIT License UpdatedDec 4, 2024 -
Microsoft-eventlog-mindmap Public
Forked from mdecrevoisier/Microsoft-eventlog-mindmapSet of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
BSD 2-Clause "Simplified" License UpdatedDec 4, 2024