
BlueTeam-Tools
Tools and Techniques for Blue Team / Incident Response

Tools and Techniques for Blue Team / Incident Response

Curated collection of cybersecurity resources, labs, and training materials covering ethical hacking, penetration testing, exploit development,…

Automated, Collection, and Enrichment Platform

An advanced memory forensics framework

Collection of forensic tools

📱 Andriller - is software utility with a collection of forensic tools for smartphones. It performs read-only, forensically sound, non-destructive…

A centralized and enhanced memory analysis platform

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

Incident Response collection and processing scripts with automated reporting scripts

A repository of sysmon configuration modules

Advanced framework for extracting digital artifacts from volatile memory (RAM) samples, enabling deep forensic analysis of system runtime state…

Cortex: a Powerful Observable Analysis and Active Response Engine

Automation and Scaling of Digital Forensics Tools

Portable, dependency-free incident response tool that automates forensic artifact collection from Unix-like systems, including memory acquisition,…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.