-
MemProcFS Public
Forked from ufrisk/MemProcFSMemProcFS
C GNU Affero General Public License v3.0 UpdatedFeb 19, 2025 -
MemProcFS-Analyzer Public
Forked from LETHAL-FORENSICS/MemProcFS-AnalyzerMemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
PowerShell GNU General Public License v3.0 UpdatedFeb 18, 2025 -
-
chainsaw Public
Forked from WithSecureLabs/chainsawRapidly Search and Hunt through Windows Forensic Artefacts
Rust GNU General Public License v3.0 UpdatedDec 28, 2024 -
Blauhaunt Public
Forked from cgosec/BlauhauntA tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts
JavaScript MIT License UpdatedNov 13, 2024 -
ThreatHunting-Keywords Public
Forked from mthcht/ThreatHunting-KeywordsAwesome list of keywords and artifacts for Threat Hunting sessions
HTML UpdatedSep 3, 2024 -
Hunting-Queries-Detection-Rules Public
Forked from SlimKQL/Hunting-Queries-Detection-RulesKQL Queries. Microsoft Defender, Microsoft Sentinel
HTML BSD 3-Clause "New" or "Revised" License UpdatedAug 22, 2024 -
deepdarkCTI Public
Forked from fastfire/deepdarkCTICollection of Cyber Threat Intelligence sources from the deep and dark web
GNU General Public License v3.0 UpdatedAug 19, 2024 -
Rapid7-Labs Public
Forked from rapid7/Rapid7-LabsRapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence, research and analytics.
YARA MIT License UpdatedJul 31, 2024 -
CVE-2024-6387-Vulnerability-Checker Public
Forked from filipi86/CVE-2024-6387-Vulnerability-CheckerThis Python script checks for the CVE-2024-6387 vulnerability in OpenSSH servers. It supports multiple IP addresses, URLs, CIDR ranges, and ports. The script can also read addresses from a file.
Python MIT License UpdatedJul 10, 2024 -
awesome-incident-response Public
Forked from meirwah/awesome-incident-responseA curated list of tools for incident response
Apache License 2.0 UpdatedJun 20, 2024 -
velociraptor-setup Public
This script will speed up velociraptor configurations using Terraform
Shell UpdatedJun 10, 2024 -
uac Public
Forked from tclahr/uacUAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler…
Shell Apache License 2.0 UpdatedApr 3, 2024 -
PersistenceSniper Public
Forked from last-byte/PersistenceSniperPowershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made w…
PowerShell UpdatedMar 31, 2024 -
ImHex Public
Forked from WerWolv/ImHex🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM.
C++ GNU General Public License v2.0 UpdatedMar 21, 2024 -
Velociraptor-Audit Public
Forked from Velocidex/AuditCollection of Audit and Compliance related VQL artifacts
Go UpdatedFeb 16, 2024 -
Linux-Process-Scanner Public
This script scans all Linux processes, uses an Virus Total API and determining if Linux processes running on you Linux devices are malicious or not.
-
Sentinel-SOC-101 Public
Forked from rod-trent/Sentinel-SOC-101Content and collateral for the Microsoft Sentinel SOC 101 series
PowerShell MIT License UpdatedFeb 12, 2024 -
LockBit Public
Forked from Tennessene/LockBitThe LockBit builder files
Batchfile UpdatedFeb 3, 2024 -
MalwareSourceCode Public
Forked from vxunderground/MalwareSourceCodeCollection of malware source code for a variety of platforms in an array of different programming languages.
Assembly UpdatedJan 18, 2024 -
ForensicMiner Public
Forked from securityjoes/ForensicMinerA really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.
PowerShell MIT License UpdatedDec 28, 2023 -
Linux-Incident-Response Public
Forked from vm32/Linux-Incident-Responsepractical toolkit for cybersecurity and IT professionals. It features a detailed Linux cheatsheet for incident response
Shell UpdatedDec 27, 2023 -
digital-forensics-lab Public
Forked from frankwxu/digital-forensics-labFree hands-on digital forensics labs for students and faculty
Roff UpdatedDec 26, 2023 -
evilginx2 Public
Forked from kgretzky/evilginx2Standalone man-in-the-middle attack framework used for phishing login credentials along with session cookies, allowing for the bypass of 2-factor authentication
Go BSD 3-Clause "New" or "Revised" License UpdatedNov 7, 2023 -
malwoverview Public
Forked from alexandreborges/malwoverviewMalwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, Th…
Python GNU General Public License v3.0 UpdatedOct 29, 2023 -
RedCsharp Public
Forked from boh/RedCsharpCollection of C# projects. Useful for pentesting and redteaming.
UpdatedOct 19, 2023 -
CAPEv2 Public
Forked from kevoreilly/CAPEv2Malware Configuration And Payload Extraction
Python Other UpdatedMay 11, 2023 -
email-header-analyzer Public
Forked from cyberdefenders/email-header-analyzerE-Mail Header Analyzer
HTML Other UpdatedApr 11, 2023 -
-
mimikatz Public
Forked from gentilkiwi/mimikatzA little tool to play with Windows security
C UpdatedNov 29, 2022