
awesome-dfir-skills
A curated collection of DFIR skills and workflows for InfoSec practitioners.

A curated collection of DFIR skills and workflows for InfoSec practitioners.

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

Mapping Corelight or Zeek data to Elastic Common Schema logs

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

Local F5 BIG-IP script that scans for Indicators of Compromise (IoCs) related to CVE-2020-5902, checking logs, files, and system integrity to detect…

CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool

PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Packetsifter…

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Analyzes .pcapng files to generate HTML reports for network traffic inspection and forensic review.

create cypher create statements for neo4j out of netstat files from multiple machines

Local proof-of-concept scanner that detects plaintext database passwords in llama-stack initialization logs, using regex pattern matching to identify…

Mapping Corelight or Zeek data to Elastic Common Schema fields

Scans jar, war, and ear files for the presence of JndiLookup.class to detect applications vulnerable to CVE-2021-44228 (Log4Shell).

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata…

Find phishing kits which use your brand/organization's files and image.