DFIR tools

I am a information security professional with interest mainly in defenses/ blue teaming. I enjoy leisure running 🏃♂️ and PC games.
Search for a command to run...

I am a information security professional with interest mainly in defenses/ blue teaming. I enjoy leisure running 🏃♂️ and PC games.
No comments yet. Be the first to comment.
Guide on setting up detection pipeline with Github Action

Indonesia leak, ransomware, and data breach monitoring

Leveraging AWS lambda and sigma for CloudTrail monitoring

Thoughts on starting cloud-centric detection assessment

This article is an excerpt from my piece originally published on cdef.id. You can read the full article here. Indicators of Compromise (IOCs) are simply evidence that a cyber intrusion has occurred. They are the digital breadcrumbs left behind by att...

even with the awesome list all over github, I kept losing tracks of cool tools, so here are some of them:
(last update 11.09.2022)
in the spirit of keep updating the resources, I'm moving this post to aldosimon/infosec-compendium
chainsaw Chainsaw provides a powerful ‘first-response’ capability to quickly identify threats within Windows event logs. It offers a generic and fast method of searching through event logs for keywords, and by identifying threats using built-in support for Sigma detection rules, and via custom Chainsaw detection rules.
DeepBlueCLI a PowerShell Module for Threat Hunting via Windows Event Logs
logparser studio event viewer and other logs parsing with SQL Language interface
velociraptor Velociraptor is a tool for collecting host based state information using The Velociraptor Query Language (VQL) queries.
osquery osquery is a SQL powered operating system instrumentation, monitoring, and analytics framework.
loki Loki - Simple IOC and YARA Scanner
KAPE Kroll Artifact Parser And Extractor, lets forensic teams collect and process forensically useful artifacts within minutes.
autposy/ TSK Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools
event ids github event id awesome list
mitre to evtx MITRE mapping to event id
lenny zeltser log cheatsheet IR critical log review cheatsheet
lenny zeltser incident survey Security incident survey cheat sheet for server administrators