A simple many-rules to many-files YARA scanner for incident response or malware zoos.
The main features of nogoodconfig/pyarascanner are: Incident Response Frameworks.
Open-source alternatives to nogoodconfig/pyarascanner include: certsocietegenerale/fir — Fast Incident Response. circl/traceroute-circl — Traceroute improved wrapper for CSIRT and CERT operators. cisagov/untitledgoosetool — Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data… crowdstrike/automactc. cyb3rward0g/helk — HELK is a containerized security information and event management environment and threat hunting platform. It provides… 0x4d31/sqhunter.
Traceroute improved wrapper for CSIRT and CERT operators
Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to run a full investigation against a customer’s Azure Active Directory (AzureAD), Azure, and M365 environments.