dfir-orc
beagle
Our great sponsors
dfir-orc | beagle | |
---|---|---|
1 | 1 | |
356 | 1,250 | |
2.2% | - | |
8.9 | 0.0 | |
3 months ago | over 1 year ago | |
C++ | Python | |
GNU Lesser General Public License v3.0 only | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
dfir-orc
-
Standard artifact gathering script
Looks great! Will dig into that. It looks like French ANSSI's DFIR-ORC. Maybe a good solution.
beagle
What are some alternatives?
TheHive - TheHive: a Scalable, Open Source and Free Security Incident Response Platform
evtx-hunter - evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.
awesome-incident-response - A curated list of tools for incident response
dfirtrack - DFIRTrack - The Incident Response Tracking Application
tenzir - Open source security data pipelines.
timesketch - Collaborative forensic timeline analysis
Cortex - Cortex: a Powerful Observable Analysis and Active Response Engine
Kuiper - Digital Forensics Investigation Platform
vast - VAST is an experimental compiler pipeline designed for program analysis of C and C++. It provides a tower of IRs as MLIR dialects to choose the best fit representations for a program analysis or further program abstraction.
RELY - RELY (Name composed on project members Romy, Esther, Lucille and Yassir) is a python tool developed to help a Digital Forensics Triage procedure on some Microsoft Windows devices.
AzureHunter - A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365
IntelOwl - IntelOwl: manage your Threat Intelligence at scale