
DFIR-LABS
Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…


Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV.…

A list of cyber-chef recipes and curated links

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Collection of forensic tools

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from…

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Distributed & real time digital forensics at the speed of the cloud

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux


A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

Python script for carving Bitlocker VMK keys
