awesome-event-ids
LinuxForensics
awesome-event-ids | LinuxForensics | |
---|---|---|
2 | 4 | |
541 | 664 | |
- | - | |
6.0 | 7.1 | |
6 months ago | 10 months ago | |
Shell | ||
MIT License | - |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
awesome-event-ids
-
Alert rules for Active Directory domain controllers hosted in Azure
This is a large list of resources regarding logging and auditing: https://github.com/stuhli/awesome-event-ids/blob/main/README.md
- Collection of Event ID resources useful for Digital Forensics and Incident Response
LinuxForensics
- Linux Forensics - Talks and Workshops
-
Linux Forensics
Also check out the Linux forensic resources at https://linuxdfir.ashemery.com/.
-
Compromised Linux VM for DF training?
The Great Hal Pomeranz made a course, with resources from Ali Hadi/Champlain College, that might help you out: https://archive.org/download/HalLinuxForensics https://github.com/ashemery/LinuxForensics
What are some alternatives?
GUN4IR - The best Lightun system you can do by yourself
MemLabs - Educational, CTF-styled labs for individuals interested in Memory Forensics
IrScrutinizer - IrScrutinizer is a program for IR signal analysis, decoding, generation and much more.
uac - UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
Digital-Forensics-Guide - Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
ThreatHunting_with_Osquery - Threat Hunting & Incident Investigation with Osquery
swap_digger - swap_digger is a tool used to automate Linux swap analysis during post-exploitation or forensics. It automates swap extraction and searches for Linux user credentials, web forms credentials, web forms emails, http basic authentication, Wifi SSID and keys, etc.