#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

Quick and dirty fix to OLE2 executing code via .hta

Tools for the Computer Incident Response Team :computer:

Differential Analysis of Malware in Memory

Powershell Empire Persistence finder

NCC Group Ransomware Simulator

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

RAM imaging utility.


Anti-keylogger/anti-rat application for Windows

Tools to enumerate Windows Firewall Hook Drivers on Windows 2000, XP and 2003

This is a workaround for CVE-2014-0993 and CVE-2014-0994 that patches on memory without the need to recompile your vulnerable software. This is not…

Selective protocol extractor from PCAPs or interfaces

Windows Process Lockdown Tool using Job Objects

Generates portable SystemTap kernel modules to mitigate CVE-2013-2094 on Enterprise Linux systems, with automated build and deployment scripts for…