
awesome-dfir-skills
A curated collection of DFIR skills and workflows for InfoSec practitioners.
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

A curated collection of DFIR skills and workflows for InfoSec practitioners.

A Zeek OpenVPN protocol analyzer, based on Spicy.

Cyber Threat Defense World Modeling

Post-Exploitation EVTX Analyzer for BloodHound Mapping

Blue Team lab focused on analyzing Apache web access logs to detect directory brute forcing and web scanning activity.

Create actionable data from your Vulnerability Scans

This repository contains an academic and technical analysis of CVE-2023-34362, a critical SQL injection vulnerability affecting the MOVEit Transfer…

Hands-on analysis of common APT attack techniques, focused on how they show up in logs and how defenders can realistically detect them.

Best Practice Auditd Configuration


IDS/IPS lab for detecting and preventing Apache ActiveMQ RCE (CVE-2023-46604) using GVM, Nmap, Snort, iptables, and UFW.

Automates Windows memory forensics and DFIR workflows with MemProcFS: YARA/ClamAV scanning, process anomaly detection, and artifact/log extraction.

Continuously fetches and cryptographically verifies key transparency log updates, maintains a condensed prefix and log tree view, and returns signed…

My first hands-on Intel 471 threat hunting workshop experience investigating CVE-2023-46604 using Elastic SIEM, vulnerability intelligence, and…

Remediation report for MegaQuagga Publishing validating the mitigation of CVE-2019-9978 through progressive defensive layering. Documents reverse…

Open source Baltic Sea shadow fleet tracker. 1200+ vessels, live AIS, cable proximity alerts. No cloud, no subscription, runs locally

Escaneo de vulnerabilidades, análisis de tráfico con Wireshark y explotación controlada del CVE-2011-2523 (vsftpd 2.3.4) en entorno de red segura.

Log4Shell (CVE-2021-44228) defense lab — nginx + Coraza WAF dynamic module + OWASP CRS v4. Educational use only.