DFIRTrack - The Incident Response Tracking Application
-
Updated
Sep 4, 2024 - Python
DFIRTrack - The Incident Response Tracking Application
AWS CloudSaga - Simulate security events in AWS
AHA is an incident management & communication framework to provide real-time alert customers when there are active AWS event(s). For customers with AWS Organizations, customers can get aggregated active account level events of all the accounts in the Organization. Customers not using AWS Organizations still benefit alerting at the account level.
A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️
Forensic toolkit for iOS sysdiagnose feature
An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.
The DNA test for websites
CLI program for automating the setup, configuration, and use of cybersecurity solutions
Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.
CLI for selecting and back-testing CloudWatch alarm configuration
Cortex-Analyzers Modified - SecTeam/CERT/SOC Security orchestration tools on steroids
systeminfo command for offline system images
Incident Response in AWS with Alexa
Highly useful Volatility-Malfind output parser for detecting Code/Process Injection patterns
QRadar to Redmine(as Ticketing System) Integration with API CALLS written in Python
Check domain in question to VT
Scope is an open source cloud forensic tool to rapidly analyse logs, detect suspicious activity and identify malicious resources. Scope supports Amazon Web Services (AWS), Google Cloud Platform (GCP) and Microsoft Azure.
FIRST.org Incident Response teams' contact information scraper
A CLI tool for generating observability queries to assist incident responders during incident investigation.
Uses the Damerau-Levenshtein distance to find suspicious tasks running on endpoints in Windows.
Add a description, image, and links to the incident-response-tooling topic page so that developers can more easily learn about it.
To associate your repository with the incident-response-tooling topic, visit your repo's landing page and select "manage topics."