
ir-rescue
A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.


A list of cyber-chef recipes and curated links

Open-source network forensics toolkit for packet analysis, port scanning, host discovery, and IP geolocation. Supports ARP, ICMP, TCP, UDP pings and…

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

A tool for processing a lot of pcaps using tshark

TCP/IP packet demultiplexer. Download from:

Wireshark plugin that correlates network traffic with threat intelligence, asset tags, and vulnerability data to accelerate forensic analysis of PCAP…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Reports on post-exploitation on honeypot exploiting vulnerable wu-ftpd (CVE-2001-0550)

Investigation and Incident Response report for LetsDefend Alert SOC335 (CVE-2024-49138 Exploitation)

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

Malware samples, analysis exercises and other interesting resources.

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Wireshark RDP resources