
DetectionLabELK
DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

🐍 High-performance, multi-threaded YARA & IOC scanner

Lua plugin to extract data from Wireshark and convert it into MISP format

Live memory analysis detecting malware IOCs in processes, modules, handles, tokens, threads, .NET assemblies, memory address space and environment…

Walk any memory dump. Find what's hidden. Linux + Windows kernel forensics from a single static Rust binary — no Python required.

Apache ActiveMQ (CVE-2023-46604) zafiyetinden LockBit ransomware aşamasına uzanan 419 saatlik sızma vakasının uçtan uca analizi, SIEM korelasyon…

VirusTotal Wanna Be - Now with 100% more Hipster

Cortex: a Powerful Observable Analysis and Active Response Engine

A DFIR tool to extract cryptocoin addresses and other indicators of compromise from binaries.

Curated collection of detection rules and IOCs extracted from DFIR engagements and malware analyses to support threat hunting, incident response, and…

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

CVE-2021-44228 DFIR Notes

Spring4Shell (CVE-2022-22965) DFIR lab with exploit simulation, Python WAF, IOC-based detection, and PCAP analysis.

My Citrix ADC NetScaler CVE-2019-19781 Vulnerability DFIR notes.

A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.

A verified map of reverse engineering and malware analysis. Disassemblers, unpacking, exploit dev, fuzzing, DFIR, and the deep-cut writeups other…

A curated knowledge base to build, run and mature a SOC (including CSIRT).

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts