
SOC/CERT/CTIの検知とインシデントレスポンス向けに、脅威インテリジェンスフィード、IoCリスト、YARAルール、DFIRツールリファレンスを厳選してまとめたリポジトリです。

これらのリストのほとんどは、detection keywordsプロジェクトで分析するツールごとに定期的に更新しています
13cubed - Investigating Windows Endpoints 13cubed.com - Windows エンドポイント
13cubed - Investigating Windows Memory 13cubed.com - Windows メモリ
13cubed - Investigating Linux Devices 13cubed.com - Linux
SANS: FOR500
SANS: FOR508
Defensive-security: Linux-live-forensics
@0gtweet - フォレンジックコース: Mastering Windows Forensics
@DebugPrivilege : 無料のフォレンジックデバッグコース InsightEngineering
チャレンジ:
tryhackme - SOC レベル1
tryHackme - SOC レベル2
letsdefend.io @chrissanders88 - letsdefend.io
Constructing Defense constructingdefense.com
SANS: SANS555
チャレンジ:
@TheDFIRReport : 既存レポートのログを使ったラボ dfir-labs
@ACEresponder: 詳細な解説とラボ付きコース aceresponder.com
@inversecos - APTエミュレーションラボ: xintra