
timesketch
Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Collaborative forensic timeline analysis platform for ingesting, searching, and annotating event logs to support incident response and DFIR…

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Read-only PowerShell security auditor for Windows endpoints and servers: checks Defender configuration, patch status, credentials, persistence,…

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…

Forensics artefact collection tool for systems running Microsoft Windows

Taxonomies used in MISP taxonomy system and can be used by other information sharing tool.

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

Ransomware decryption and script deobfuscation utilities from a threat intelligence team, designed for incident responders and malware analysts.

Small tool to play with IOCs caused by Imageload events

Defensive detection & mitigation tool for CVE-2026-31431 ("Copy Fail") — Linux kernel algif_aead LPE. No exploit code included.

Inspect live Windows system internals: processes, services, network, kernel callbacks, SSDT, and per-process anomalies; detect hooks and rootkits…

😎 Awesome list of all things related to Microsoft Entra

A binary and file access authorization system for macOS.

A PoC ransomware sample to test out your ransomware response strategy.

Digital Forensics Intelligence Framework

Basic log analysis tool to detect impossible travel via IP address geographic information

Windows Process Lockdown Tool using Job Objects