live-response
There are 11 repositories under live-response topic.
tclahr/uac
UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
evild3ad/MemProcFS-Analyzer
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
cyb3rmik3/MDE-DFIR-Resources
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
evild3ad/Collect-MemoryDump
Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
lawndoc/mediator
An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.
op7ic/unix_collector
unix_collector is a Live Response collection script for Incident Response on UNIX-like systems using native binaries. Supports AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
21gramaz/Powershell-SIR
This is a Live Response script to help incident responders to acquire data, contain and recover.
LazyAlpaka/ifrit
Incident Forensic Response In Terminal script for linux
iidx/PSListCopy
File and file meta information collect using PowerShell in Live Response environment.
0xThiebaut/Zipit
A Firefox extension to encrypt files downloaded through Microsoft 365 Defender's Live Response Sessions.
iidx/IIS-AppHostParser
Parse IIS applicationHost.config to generate CSV file.