
awesome-dfir-skills
A curated collection of DFIR skills and workflows for InfoSec practitioners.

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Searches For Threat Hunting and Security Analytics

Incident Response collection and processing scripts with automated reporting scripts

SQL powered operating system instrumentation, monitoring, and analytics.

A repository of sysmon configuration modules

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of…

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

This repository contains a list of new remediation scripts.

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI