awesome-incident-response
DFIRMindMaps
Our great sponsors
awesome-incident-response | DFIRMindMaps | |
---|---|---|
4 | 3 | |
7,114 | 475 | |
- | - | |
5.6 | 1.8 | |
30 days ago | over 1 year ago | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
awesome-incident-response
-
Cybersecurity Repositories
Incident Response
- Questions about getting into DF
-
I started a new role as a Incident Response Analyst and wanted to get some advice.
Here is a good github page that discusses tons of IR stuff. https://github.com/meirwah/awesome-incident-response
-
Has this sub done any curated reasearch collection sharing?
GitHub sounds totally viable. You might consider styling it after something like Awesome Lists. (Ex: Awesome Incident Response). But yes, totally viable.
DFIRMindMaps
What are some alternatives?
Kuiper - Digital Forensics Investigation Platform
RecuperaBit - A tool for forensic file system reconstruction.
cyberchef-recipes - A list of cyber-chef recipes and curated links
KapeFiles - This repository serves as a place for community created Targets and Modules for use with KAPE.
dfir-orc - Forensics artefact collection tool for systems running Microsoft Windows
ccl_chrome_indexeddb - (Sometimes partial) Python re-implementations of the technologies involved in reading various data sources in Chrome-esque applications.
DevSecOps - Ultimate DevSecOps library
sysmon-config - Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.
awesome-sre - A curated list of Site Reliability and Production Engineering resources.
EventTranscript.db-Research - A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.
awesome-pentest - A collection of awesome penetration testing resources, tools and other shiny things
awesome-forensics - A curated list of awesome forensic analysis tools and resources