LinuxForensics
ThreatHunting_with_Osquery
Our great sponsors
LinuxForensics | ThreatHunting_with_Osquery | |
---|---|---|
4 | 3 | |
662 | 190 | |
- | - | |
7.1 | 0.0 | |
10 months ago | about 2 years ago | |
Shell | ||
- | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
LinuxForensics
- Linux Forensics - Talks and Workshops
-
Linux Forensics
Also check out the Linux forensic resources at https://linuxdfir.ashemery.com/.
-
Compromised Linux VM for DF training?
The Great Hal Pomeranz made a course, with resources from Ali Hadi/Champlain College, that might help you out: https://archive.org/download/HalLinuxForensics https://github.com/ashemery/LinuxForensics
ThreatHunting_with_Osquery
- Threat Hunting & Incident Investigation with Osquery: The objective of this repo is to share 100+ hunting queries (osquery) that will help cyber threat analysts (hunter/investigator) in their hunting or investigation exercises - for Linux & Windows.
- Threat Hunting & Incident Investigation with Osquery
- Threat Hunting and Incident Investigation with Osquery
What are some alternatives?
MemLabs - Educational, CTF-styled labs for individuals interested in Memory Forensics
cyberchef-recipes - A list of cyber-chef recipes and curated links
uac - UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
awesome-incident-response - A curated list of tools for incident response
awesome-event-ids - Collection of Event ID ressources useful for Digital Forensics and Incident Response
CyberThreatHunting - A collection of resources for Threat Hunters - Sponsored by Falcon Guard
swap_digger - swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux user credentials, web forms credentials, web forms emails, http basic authentication, Wifi SSID and keys, etc.