155 repository-uri
Tools for digital forensics, incident response, and threat hunting.
Explore 155 awesome GitHub repositories matching part of an awesome list · Forensics and Incident Response. Refine with filters or upvote what's useful.
This project is a command-line forensic toolkit designed for the investigation and security auditing of mobile devices. It provides a framework for collecting system logs, application data, and forensic artifacts to identify potential security breaches, unauthorized access, or evidence of malicious activity. The utility employs a modular extraction architecture that parses diverse file formats and system logs into a standardized, normalized data structure. By utilizing this unified format, the tool performs both heuristic analysis of system metadata and pattern matching against structured thr
Toolkit for mobile device forensic compromise analysis.
Sysdig is a Linux system observability tool and kernel event analyzer designed for capturing and analyzing kernel-level system calls and operating system events. It functions as a system call tracer and container security monitor, providing deep visibility into the activity of machines, virtual machines, and containers. The project specializes in non-invasive container inspection, allowing for the monitoring of container activity and resource usage without modifying the container environment or adding instrumentation. It enables the recording of detailed system traces into binary files for re
System exploration and troubleshooting tool for Linux.
This project is a collection of instructional resources and manuals providing strategic defense frameworks for protecting cryptocurrency assets and digital identities. It serves as a security guide for mitigating blockchain-based exploits, managing digital wallets, and implementing risk frameworks to prevent the theft of digital assets. The documentation provides detailed handbooks on wallet security, including the management of private keys, the use of hardware wallets, and secure transaction signing. It offers specialized guidance on anti-phishing defense and the identification of social en
Includes protocols for securing system state and volatile logs to maintain evidentiary integrity.
Dispatch is an incident response orchestration platform that automates the coordination of detection, participant assembly, and task tracking across existing communication and project management tools. It provides a web-configurable state machine to manage incident lifecycle transitions, with template-driven incident models that define types, priorities, and severity levels. The platform enforces role-based access control to map user roles to specific actions and data access, while maintaining a database-backed audit trail of all incident events and system changes for compliance and post-incid
Manages incident response workflows and coordination.
GRR este o platformă distribuită de răspuns la incidente și un orchestrator asincron de sarcini criminalistice. Acesta funcționează ca un framework de criminalistică la distanță conceput pentru a colecta și analiza date volatile, memoria sistemului și artefacte digitale de la gazde la distanță în timpul răspunsului la incidente de securitate. Sistemul operează ca un sistem de triaj la distanță pentru endpoint-uri, utilizând o arhitectură coordonată pentru a gestiona o flotă de agenți. Permite execuția sarcinilor de investigație pe mai multe sisteme, permițând căutarea fișierelor și a regiștrilor pe o flotă mare de mașini pentru a identifica gazdele compromise. Platforma oferă capabilități pentru analiza criminalistică digitală, inclusiv capacitatea de a analiza sisteme de fișiere brute și de a genera cronologii ale evenimentelor de sistem. Include, de asemenea, instrumente pentru monitorizarea flotei enterprise pentru a urmări utilizarea resurselor și a programa sarcini criminalistice recurente.
Captures specific binaries, memory dumps, and network traffic from remote targets for security investigation.
Tetragon este un set de instrumente pentru securitatea runtime și observabilitate bazat pe eBPF, conceput pentru medii Linux și Kubernetes. Acesta funcționează ca un manager de politici de securitate, agent de observabilitate și motor de impunere a regulilor, conectându-se la funcțiile kernel-ului și la tracepoint-uri pentru a detecta escaladarea privilegiilor, evadarea din containere și activitățile neautorizate ale sistemului. Proiectul se distinge prin capacitatea de a efectua impunerea regulilor în timp real, direct în kernel, permițând terminarea sincronă a proceselor malițioase sau modificarea valorilor returnate de funcții înainte ca un apel de sistem să se finalizeze. Oferă o integrare profundă cu Kubernetes prin sincronizarea identităților containerelor și maparea evenimentelor de nivel scăzut din kernel direct către pod-uri și namespace-uri. Capabilitățile sale mai largi acoperă auditarea completă a apelurilor de sistem, monitorizarea conexiunilor de rețea și verificarea integrității fișierelor. Sistemul suportă gestionarea dinamică a politicilor și oferă instrumente de diagnosticare pentru monitorizarea performanței BPF și a utilizării resurselor. Deployment-ul este suportat în clustere Kubernetes prin Helm charts, precum și prin containere standalone și pachete native pentru sistemele de operare.
eBPF-based security observability and runtime enforcement.
Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho
Captures network traffic, binaries, memory dumps, and file artifacts for post-incident investigation and compliance.
HELK este un mediu containerizat de gestionare a informațiilor și evenimentelor de securitate (SIEM) și o platformă de threat hunting. Acesta oferă o implementare axată pe securitate a stack-ului ELK, combinând Elasticsearch, Logstash și Kibana într-o platformă specializată pentru investigarea log-urilor și descoperirea modelelor ascunse în datele de securitate ale rețelei și sistemului. Proiectul funcționează ca o suită de știință a datelor de securitate, integrând notebook-uri computaționale interactive și instrumente de procesare distribuită pentru a rula machine learning și analize grafice pe log-urile de securitate. Acest lucru permite identificarea modelelor de atac ascunse și a anomaliilor prin maparea relațiilor bazată pe grafuri. Platforma acoperă o suprafață largă a operațiunilor de securitate, inclusiv implementarea SIEM, agregarea log-urilor și căutarea bazată pe indexare. Utilizează o infrastructură bazată pe containere pentru a implementa setul complet de instrumente pentru analiza log-urilor de securitate și threat hunting.
Hunting ELK stack with advanced analytic capabilities.
Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o
Provides a comprehensive platform for collecting and analyzing host-based artifacts to investigate security breaches.
Rapidly Search and Hunt through Windows Forensic Artefacts
Rapid search and hunting tool for Windows event logs.
Collaborative forensic timeline analysis
Collaborative platform for forensic timeline analysis.
LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to
Visualizes and analyzes Windows logon events.
Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment
Threat hunting and timeline generator for Windows logs.
OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to identify security breaches. It functions as a host-based intrusion detection system and telemetry collector, gathering detailed data on process, network, and file activity. The system includes a dockerized security stack that bundles search, logging, and visualization tools into containers for analyzing endpoint telemetry. It features a security event visualizer that maps process lineage and indexes logs to facilitate root-cause analysis of attacks. The platform provides capabi
Open-source endpoint detection and response platform.
DeepBlueCLI - a PowerShell Module for Threat Hunting via Windows Event Logs
PowerShell module for threat hunting via event logs.
Shuffle: A general purpose security automation platform. Our focus is on collaboration and resource sharing.
General-purpose security automation and orchestration platform.
DEPRECATED - MozDef: Mozilla Enterprise Defense Platform
Security defense and monitoring platform.
Sysmon for Linux
Sysmon implementation for Linux systems.
Super timeline all the things
Extracts and aggregates timestamps from system files.
Rekall Memory Forensic Framework
Framework for extracting and analyzing digital artifacts.