/threat-hunting-malware-analysis-incident-response

Some portable tools, some YARA, some Python, and a little bit of love. Not all of these tools can be used in incident response. Use PEs with caution.

Primary LanguageYARA

Tools of the Trade

If you have any issues with a tool here, or have questions about usage, or really anything, please reach out and I will be glad to help.

The tools here are broad in function but have many uses in the Triage/Threat Hunting/Incident Response fields. Be careful and do your own research with PEs you find on the internet!

Tools like Seatbelt can be compiled directly from their source code, while triage-ir-v1 cannot. I have determined that these tools are safe, but again, do your own research!