Project Awesome project awesome

Incident Response

Collection 8.9k stars GitHub

IR Tools Collection

Adversary Emulation

APTSimulator 2.7k updated 6mo ago

Windows Batch script that uses a set of tools and output files to make a system look as if it was compromised.

Atomic Red Team (ART) 11.7k updated 2d ago

Small and highly portable detection tests mapped to the MITRE ATT&CK Framework.

AutoTTP 259 updated 2y ago

Automated Tactics Techniques & Procedures. Re-running complex sequences manually for regression tests, product evaluations, generate data for researchers.

Caldera 6.8k updated 5d ago

Automated adversary emulation system that performs post-compromise adversarial behavior within Windows Enterprise networks. It generates plans during operation using a planning system and a pre-configured adversary model based on the Adversarial Tactics, Techniques & Common Knowledge (ATT&CK) project.

DumpsterFire 1.0k updated 5y ago

Modular, menu-driven, cross-platform tool for building repeatable, time-delayed, distributed security events. Easily create custom event chains for Blue Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations.

Metta 1.1k updated 7y ago

Information security preparedness tool to do adversarial simulation.

Network Flight Simulator

Lightweight utility used to generate malicious network traffic and help security teams to evaluate security controls and network visibility.

Red Team Automation (RTA) 1.1k updated 7y ago

RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK.

RedHunt-OS 1.3k updated 1y ago

Virtual machine for adversary emulation and threat hunting.

CimSweep 658 updated 6y ago

Suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.

CIRTkit 150 updated 9y ago

CIRTKit is not just a collection of tools, but also a framework to aid in the ongoing unification of Incident Response and Forensics investigation processes.

Doorman 621 updated 3y ago

osquery fleet manager that allows remote management of osquery configurations retrieved by nodes. It takes advantage of osquery's TLS configuration, logger, and distributed read/write endpoints, to give administrators visibility across a fleet of devices with minimal overhead and intrusiveness.

Falcon Orchestrator

Extendable Windows-based application that provides workflow automation, case management and security response functionality.

Flare 8.5k updated 5d ago

A fully customizable, Windows-based security distribution for malware analysis, incident response, penetration testing.

Fleetdm 6.2k updated 2d ago

State of the art host monitoring platform tailored for security experts. Leveraging Facebook's battle-tested osquery project, Fleetdm delivers continuous updates, features and fast answers to big questions.

GRR Rapid Response 5.0k updated 1mo ago

Incident response framework focused on remote live forensics. It consists of a python agent (client) that is installed on target systems, and a python server infrastructure that can manage and talk to the agent. Besides the included Python API client, PowerGRR provides an API client library in PowerShell working on Windows, Linux and macOS for GRR automation and scripting.

IRIS 1.4k updated 1mo ago

IRIS is a web collaborative platform for incident response analysts allowing to share investigations at a technical level.

Kuiper 877 updated 1y ago

Digital Forensics Investigation Platform

Matano 1.7k updated 1y ago

Open source serverless security lake platform on AWS that lets you ingest, store, and analyze petabytes of security data into an Apache Iceberg data lake and run realtime Python detections as code.

MozDef 2.2k (archived)

Automates the security incident handling process and facilitate the real-time activities of incident handlers.

MutableSecurity 50 (archived)

CLI program for automating the setup, configuration, and use of cybersecurity solutions.

nightHawk 612 updated 6y ago

Application built for asynchronous forensic data presentation using ElasticSearch as the backend. It's designed to ingest Redline collections.

SOC Multi-tool 416 updated 10mo ago

A powerful and user-friendly browser extension that streamlines investigations for security professionals.

Velociraptor 3.8k updated 2d ago

Endpoint visibility and collection tool

Zentral 848 updated 2d ago

Combines osquery's powerful endpoint inventory features with a flexible notification and action framework. This enables one to identify and react to changes on OS X and Linux clients.

Dissect 1.1k updated 28d ago

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (part of NCC Group).

Evidence Collection

Acquire 119 updated 15d ago

Acquire is a tool to quickly gather forensic artifacts from disk images or a live system into a lightweight container. This makes Acquire an excellent tool to, among others, speedup the process of digital forensic triage. It uses Dissect to gather that information from the raw disk, if possible.

artifactcollector 307 updated 10mo ago

The artifactcollector project provides a software that collects forensic artifacts on systems.

bulk_extractor 1.3k updated 1mo ago

Computer forensics tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures. Because of ignoring the file system structure, the program distinguishes itself in terms of speed and thoroughness.

Cold Disk Quick Response 343 updated 3y ago

Streamlined list of parsers to quickly analyze a forensic image file (dd, E01, .vmdk, etc) and output nine reports.

CyLR 718 updated 3y ago

The CyLR tool collects forensic artifacts from hosts with NTFS file systems quickly, securely and minimizes impact to the host.

Forensic Artifacts 1.2k updated 1mo ago

Digital Forensics Artifact Repository

ir-rescue 488 updated 5y ago

Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Margarita Shotgun 253 updated 5y ago

Command line utility (that works with or without Amazon EC2 instances) to parallelize remote memory acquisition.

SPECTR3

Acquire, triage and investigate remote evidence via portable iSCSI readonly access

UAC 1.3k updated 11d ago

UAC (Unix-like Artifacts Collector) is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.

Log Analysis Tools

AppCompatProcessor 209 updated 4y ago

AppCompatProcessor has been designed to extract additional value from enterprise-wide AppCompat / AmCache data beyond the classic stacking and grepping techniques.

APT Hunter 1.4k updated 1y ago

APT-Hunter is Threat Hunting tool for windows event logs.

Chainsaw 3.5k updated 23d ago

Chainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows event logs.

Hayabusa 3.1k updated 4d ago

Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool created by the Yamato Security group in Japan.

Lorg 213 updated 7y ago

Tool for advanced HTTPD logfile security analysis and forensics.

Logdissect

CLI utility and Python API for analyzing log files and other data.

LogonTracer 3.1k updated 5mo ago

Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.

Sigma 10.2k updated 6d ago

Generic signature format for SIEM systems already containing an extensive ruleset.

StreamAlert 2.9k updated 2y ago

Serverless, real-time log data analysis framework, capable of ingesting custom data sources and triggering alerts using user-defined logic.

SysmonSearch 430 updated 2y ago

SysmonSearch makes Windows event log analysis more effective and less time consuming by aggregation of event logs.

WELA 92 updated 2d ago

Windows Event Log Analyzer aims to be the Swiss Army knife for Windows event logs.

Zircolite 794 updated 3d ago

A standalone and fast SIGMA-based detection tool for EVTX or JSON.

Memory Analysis Tools

AVML 1.1k updated 6d ago

A portable volatile memory acquisition tool for Linux.

Evolve 260 updated 8y ago

Web interface for the Volatility Memory Forensics Framework.

inVtero.net 296 updated 2y ago

Advanced memory analysis for Windows x64 with nested hypervisor support.

LiME 2.0k updated yesterday

Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, formerly called DMD.

MalConfScan 495 updated 2y ago

MalConfScan is a Volatility plugin extracts configuration data of known malware. Volatility is an open-source memory forensics framework for incident response and malware analysis. This tool searches for malware in memory images and dumps configuration data. In addition, this tool has a function to list strings to which malicious code refers.

MemProcFS 4.1k updated 23d ago

MemProcFS is an easy and convenient way of viewing physical memory as files in a virtual file system.

Orochi 265 updated 1mo ago

Orochi is an open source framework for collaborative forensic memory dump analysis.

Volatility 8.0k (archived)

Advanced memory forensics framework.

Volatility 3 4.0k updated 9d ago

The volatile memory extraction framework (successor of Volatility)

VolatilityBot 269 updated 4y ago

Automation tool for researchers cuts all the guesswork and manual tasks out of the binary extraction phase, or to help the investigator in the first steps of performing a memory analysis investigation.

VolDiff 197 (archived)

Malware Memory Footprint Analysis based on Volatility.

Other Tools

Diffy 631 updated 2y ago

DFIR tool developed by Netflix's SIRT that allows an investigator to quickly scope a compromise across cloud instances (Linux instances on AWS, currently) during an incident and efficiently triaging those instances for followup actions by showing differences against a baseline.

domfind 25 updated 6y ago

Python DNS crawler for finding identical domain names under different TLDs.

Fileintel

Pull intelligence per file hash.

HELK 3.9k updated 1y ago

Threat Hunting platform.

Hindsight 1.4k updated 21d ago

Internet history forensics for Google Chrome/Chromium.

Hostintel 274 updated 5y ago

Pull intelligence per host.

imagemounter 127 updated 3y ago

Command line utility and Python package to ease the (un)mounting of forensic disk images.

Kansa 1.6k updated 3y ago

Modular incident response framework in PowerShell.

MFT Browser 327 updated 1y ago

MFT directory tree reconstruction & record info.

Munin

Online hash checker for VirusTotal and other services.

PowerSponse 40 updated 4y ago

PowerSponse is a PowerShell module focused on targeted containment and remediation during security incident response.

PyaraScanner 27 updated 7y ago

Very simple multi-threaded many-rules to many-files YARA scanning Python script for malware zoos and IR.

rastrea2r 241 updated 4y ago

Allows one to scan disks and memory for IOCs using YARA on Windows, Linux and OS X.

Raccine 974 updated 2y ago

A Simple Ransomware Protection

Stenographer 1.8k (archived)

Packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. It stores as much history as it possible, managing disk usage, and deleting when disk limits are hit. It's ideal for capturing the traffic just before and during an incident, without the need explicit need to store all of the network traffic.

sqhunter

Threat hunter based on osquery and Salt Open (SaltStack) that can issue ad-hoc or distributed queries without the need for osquery's tls plugin. sqhunter allows you to query open network sockets and check them against threat intelligence sources.

sysmon-config 5.4k updated 1y ago

Sysmon configuration file template with default high-quality event tracing

sysmon-modular 3.0k updated 1y ago

A repository of sysmon configuration modules

traceroute-circl 40 updated 1y ago

Extended traceroute to support the activities of CSIRT (or CERT) operators. Usually CSIRT team have to handle incidents based on IP addresses received. Created by Computer Emergency Response Center Luxembourg.

Windows Evidence Collection

LOKI 3.7k updated 2mo ago

Free IR scanner for scanning endpoint with yara rules and other indicators(IOCs).

AChoir 191 updated 3y ago

Framework/scripting tool to standardize and simplify the process of scripting live acquisition utilities for Windows.

DFIR ORC 434 updated 1y ago

DFIR ORC is a collection of specialized tools dedicated to reliably parse and collect critical artifacts such as the MFT, registry hives or event logs. DFIR ORC collects data, but does not analyze it: it is not meant to triage machines. It provides a forensically relevant snapshot of machines running Microsoft Windows. The code can be found on GitHub.

FastIR Collector 520 updated 5y ago

Tool that collects different artifacts on live Windows systems and records the results in csv files. With the analyses of these artifacts, an early compromise can be detected.

Fibratus 2.4k updated yesterday

Tool for exploration and tracing of the Windows kernel.

Hoarder 210 updated 5y ago

Collecting the most valuable artifacts for forensics or incident response investigations.

Invoke-LiveResponse 150 updated 4y ago

Invoke-LiveResponse is a live response tool for targeted collection.

IRTriage 138 updated 10y ago

Incident Response Triage - Windows Evidence Collection for Forensic Analysis.

MEERKAT 481 updated 1y ago

PowerShell-based triage and threat hunting for Windows.

Panorama 41 updated 9y ago

Fast incident overview on live Windows systems.

PowerForensics 1.4k updated 2y ago

Live disk forensics platform, using PowerShell.

PSRecon 492 updated 8y ago

PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained locally.

RegRipper 687 updated 1y ago

Open source tool, written in Perl, for extracting/parsing information (keys, values, data) from the Registry and presenting it for analysis.