
spacesiren
A honey token manager and alert system for AWS.

A honey token manager and alert system for AWS.

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

Automated PowerShell script for forensically sound Windows memory acquisition, including crash/raw dumps, pagefile collection, triage artifacts, and…

A Software as a Service (SaaS) log collection framework.

Incident Response Triage - Windows Evidence Collection for Forensic Analysis

Collects and organizes malware indicators of compromise (IOCs) for rapid threat detection, incident response, and actionable intelligence sharing.

Detect and log CVE-2019-19781 scan and exploitation attempts.

Artifact collection tool for *nix systems

Detection-as-code platform that automates cloud security incident response by correlating artifacts, analyzing IOCs, and orchestrating…

Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with…

Curated Indicators of Compromise and YARA rules from Zscaler ThreatLabz public reports for threat hunting, malware research, and detection…

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Agent-based ransomware simulation toolkit for controlled detection testing across Windows endpoints and network assets, with a cross-platform…

Modular incident response toolkit for collecting forensic data from potentially infected macOS endpoints, capturing browser artifacts, persistence…

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

Automates incident response tasks via Carbon Black Response API: file/registry deletion, process killing, sensor isolation, binary collection, and…