
DFIRArtifactMuseum
The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

The goal of this repo is to archive artifacts from all versions of various OS's and categorizing them by type. This will help with artifact…

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

A list of cyber-chef recipes and curated links

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

Everything related to Linux Forensics

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-1…

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Apache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon…

🔬 Jupyter notebook to help automate some of the forensic analysis related to Citrix Netscalers compromised via CVE-2019-19781

Hands-on DFIR challenges covering digital forensics, incident response, malware analysis, and threat hunting with CTF-style flags and real-world…

CVE-2021-44228 DFIR Notes

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

My Citrix ADC NetScaler CVE-2019-19781 Vulnerability DFIR notes.

A Repository to Track Anti-Forensic Techniques

A verified map of reverse engineering and malware analysis. Disassemblers, unpacking, exploit dev, fuzzing, DFIR, and the deep-cut writeups other…

A curated knowledge base to build, run and mature a SOC (including CSIRT).

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts