pricklypete-dfir's Stars
NationalSecurityAgency/ghidra
Ghidra is a software reverse engineering (SRE) framework
FreeCAD/FreeCAD
This is the official source code of FreeCAD, a free and opensource multiplatform 3D parametric modeler.
Velocidex/velociraptor
Digging Deeper....
salesforce/ja3
JA3 is a standard for creating SSL client fingerprints in an easy to produce and shareable way.
xaitax/TotalRecall
This tool extracts and displays data from the Recall feature in Windows 11, providing an easy way to access information about your PC's activity snapshots.
microsoft/Microsoft-365-Defender-Hunting-Queries
Sample queries for Advanced hunting in Microsoft 365 Defender
gamelinux/passivedns
A network sniffer that logs all DNS server replies for use in a passive DNS setup
strandjs/IntroLabs
These are the labs for my Intro class. Yes, this is public. Yes, this is intentional.
philhagen/sof-elk
Configuration files for the SOF-ELK VM
FalconForceTeam/FalconFriday
Hunting queries and detections
AndrewRathbun/DFIRMindMaps
A repository of DFIR-related Mind Maps geared towards the visual learners!
Neo23x0/sysmon-config
Sysmon configuration file template with default high-quality event tracing
corelight/zeek-cheatsheets
Zeek Log Cheatsheets
nasbench/MindMaps
#ThreatHunting #DFIR #Malware #Detection Mind Maps
CrowdStrike/SuperMem
A python script developed to process Windows memory images based on triage type.
MalwareArchaeology/ARTHIR
ATT&CK Remote Threat Hunting Incident Response
Subterfuge-Framework/Subterfuge
Framework for Man-In-The-Middle attacks
corelight/community-id-spec
An open standard for hashing network flows into identifiers, a.k.a "Community IDs".
CrowdStrike/logscale-community-content
This repository contains Community and Field contributed content for LogScale
ethack/tht
Threat Hunting Toolkit is a Swiss Army knife for threat hunting, log processing, and security-focused data science
philhagen/ip2geo
Script to perform bulk local GeoIP lookups (ASN and geo) for IP addresses
EZToolsManuals/EZToolsManuals
A repo hosting the Markua content for the EZ Tools manuals hosted on Leanpub
corelight/threat-hunting-guide
philhagen/for572-scripts
A completely unsupported set of scripts used in SANS FOR572, Advanced Network Forensics and Analysis
philhagen/timeshift
A python script to shift the timestamp on syslog data. Useful for forensicators combating time skew.
secshoggoth/presentations
Repository of the presentations that I have given and released.
kiddinn/l2t-tools
Automatically exported from code.google.com/p/l2t-tools
AndrewRathbun/KapeDocs
Documentation repository
AndrewRathbun/JumpList
philhagen/yersinia-web
Yersinia Web