utvikleren's Stars
BurntSushi/ripgrep
ripgrep recursively searches directories for a regex pattern while respecting your gitignore
samratashok/nishang
Nishang - Offensive PowerShell for red team, penetration testing and offensive security.
meirwah/awesome-incident-response
A curated list of tools for incident response
volatilityfoundation/volatility
An advanced memory forensics framework
MISP/MISP
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
Azure/Azure-Sentinel
Cloud-native SIEM for intelligent security analytics for your entire enterprise.
Yara-Rules/rules
Repository of yara rules
Cyb3rWard0g/HELK
The Hunting ELK
CyberMonitor/APT_CyberCriminal_Campagin_Collections
APT & CyberCriminal Campaign Collection
InQuest/awesome-yara
A curated list of awesome YARA rules, tools, and people.
GAM-team/GAM
command line management for Google Workspace
DidierStevens/DidierStevensSuite
Please no pull requests for this repository. Thanks!
Yelp/osxcollector
A forensic evidence collection & analysis toolkit for OS X
Kevin-Robertson/Invoke-TheHash
PowerShell Pass The Hash Utils
TheresAFewConors/Sooty
The SOC Analysts all-in-one CLI tool to automate and speed up workflow.
microsoft/avml
AVML - Acquire Volatile Memory for Linux
nsacyber/Event-Forwarding-Guidance
Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsacyber
jordan-wright/dumpmon
Information Dump Monitor
pstirparo/mac4n6
Collection of forensics artifacts location for Mac OS X and iOS
davidpany/WMI_Forensics
srcecde/aws-lambda-cheatsheet
AWS Lambda cheatsheet.
halpomeranz/lmg
Script for automating Linux memory capture and analysis
ThreatResponse/margaritashotgun
Remote Memory Acquisition Tool
securityclippy/elasticintel
Serverless, low cost, threat intel aggregation for enterprise or personal use, backed by ElasticSearch.
Hestat/lw-yara
Yara Ruleset for scanning Linux servers for shells, spamming, phishing and other webserver baddies
Resistor52/cloud_dfir_demo
Demonstration of EC2 Forensic Techniques
krlplm/parseemailheader
parseemailheader is a simple stand-alone executable file which could be used to analyze the email headers by printing the header content in human-readable format.