How this analysis was created: This summary and feature list were written by an AI model that read the project's README and public documentation pages. Each feature links to the documentation it came from; stars, license and language come straight from the GitHub API. The model does not read the source code, and the analysis is refreshed when the project is re-analysed. Learn more on our About page.
A tool to help forensicate offline docker acquisitions
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
Pafish is an anti-analysis sandbox detector and virtualization environment tester. It serves as a diagnostic utility to identify if a system is running inside a virtual machine or a malware analysis sandbox by executing common anti-analysis techniques. The tool validates the effectiveness of various evasion methods and supports research into sandbox detection. It tests whether a target system can be recognized as a virtualized environment to help improve the stealth of malware analysis environments. Detection is achieved through a variety of behavioral checks, including hardware artifact ana
A toolkit for the post-mortem examination of Docker containers from forensic HDD copies
The main features of docker-forensics-toolkit/toolkit are: Docker Forensics, Container Forensics, Digital Forensics.
Open-source alternatives to docker-forensics-toolkit/toolkit include: google/docker-explorer — A tool to help forensicate offline docker acquisitions. ahmedkhlief/apt-hunter — APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT… andrewrathbun/dfirartifactmuseum — DFIR Artifact Museum. andrewrathbun/dfirmindmaps — This is a repository to centralize DFIR-related Mind Maps created with any Mind Mapping suites. The main point of this… anssi-fr/adtimeline — 1. The ADTimeline PowerShell script 1. Description 2. Prerequisites 3. Usage 4. Files generated 5. Custom groups 2.… a0rtega/pafish — Pafish is an anti-analysis sandbox detector and virtualization environment tester. It serves as a diagnostic utility…