awesome-repositories.com
博客
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目关于排名机制媒体报道MCP 服务器
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Bypass007 avatar

Bypass007/Emergency-Response-Notes

0
View on GitHub↗
5,551 星标·1,298 分支·11 次浏览bypass007.github.io/Emergency-Response-Notes↗

Emergency Response Notes

Emergency-Response-Notes 是一套用于执行取证分析、事件响应、入侵识别和恶意软件修复的技术参考文档和手册。它作为一个事件响应知识库和入侵分析框架,帮助识别安全攻击期间使用的 Web shell、隐藏后门和持久化机制。

该项目利用基于案例研究的知识库,将现实世界的攻击场景映射到具体的缓解和恢复步骤。它提供了数字取证手册和恶意软件修复指南,用于检测和清除勒索软件、加密货币挖矿程序及其他恶意软件载荷。

该项目的范围涵盖数字取证、入侵检测工作流和主动威胁狩猎。它包括用于中和安全事件、通过日志取证重建事件以及在各种操作系统上实施跨平台缓解策略的程序化策略。

Features

  • Forensic Analysis Playbooks - Provides detailed forensic playbooks and checklists for identifying unauthorized system access and hidden backdoors.
  • Digital Forensics and Analysis - Serves as a comprehensive resource for performing digital forensics and analysis to trace attacker activity.
  • Forensic Investigation Playbooks - Provides step-by-step procedures for examining system logs and tracing attacker activity.
  • Response Case Studies - Provides a case-study-based knowledge base mapping real-world attack scenarios to recovery steps.
  • Persistence Mechanisms - Identifies privilege maintenance and persistence techniques used by attackers to maintain access to compromised hosts.
  • Intrusion Analysis Frameworks - Provides a structured reference for identifying web shells, hidden backdoors, and persistence mechanisms.
  • Intrusion Detection Workflows - Provides workflows for identifying unauthorized access and hidden backdoors using forensic checklists.
  • Malware Removal - Provides detailed guides and techniques for the removal of ransomware, cryptominers, and other malicious software.
  • Recovery Workflows - Defines sequential operational checklists for neutralizing threats and removing malicious payloads from compromised systems.
  • Malware - Provides technical documentation for detecting and removing ransomware, cryptominers, and other malicious payloads.
  • Incident Response Resources - Supplies playbooks and checklists for responding to and recovering from active security breaches and web shell injections.
  • Backdoor Detection Techniques - Locates hidden webshells and persistence mechanisms used by attackers to maintain long-term access.
  • System Forensic Analysis - Offers structured checklists and methodologies for performing system-level forensic analysis to identify unauthorized access.
  • Authentication Attack Analysis - Analyzes real-world attack scenarios including brute-force and hijacking to develop countermeasures.
  • Cross-Platform Mitigation Strategies - Documents different recovery techniques tailored to the specific architecture of various operating systems.
  • Forensic Log Auditors - Enables the examination of system and database logs to reconstruct security events and trace activity.
  • Threat Hunting Workflows - Documents proactive threat hunting workflows based on real-world attack case studies.
  • Security Event Reconstruction - Analyzes system and database logs by matching known attacker activity signatures to reconstruct security events.
  • Incident Response Guides - Practical field notes for security engineers during incidents.

Star 历史

bypass007/emergency-response-notes 的 Star 历史图表bypass007/emergency-response-notes 的 Star 历史图表

AI 搜索

探索更多 awesome 仓库

用简单的语言描述您的需求 —— AI 将根据相关性为您从数千个精选开源项目中进行排序。

Start searching with AI

Emergency Response Notes 的开源替代方案

相似的开源项目,按与 Emergency Response Notes 的功能重合度排序。
  • neo23x0/lokiNeo23x0 的头像

    Neo23x0/Loki

    3,763在 GitHub 上查看↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Python
    在 GitHub 上查看↗3,763
  • google/grrgoogle 的头像

    google/grr

    5,074在 GitHub 上查看↗

    GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote forensics framework designed to collect and analyze volatile data, system memory, and digital artifacts from remote hosts during security incident response. The system operates as a remote endpoint triage system, utilizing a coordinated architecture to manage a fleet of agents. It enables the execution of investigative tasks across multiple systems, allowing for the search of files and registries across a large fleet of machines to identify compromised hosts. The platform pro

    Python
    在 GitHub 上查看↗5,074
  • withsecurelabs/chainsawWithSecureLabs 的头像

    WithSecureLabs/chainsaw

    3,446在 GitHub 上查看↗

    Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa

    Rustattackblueteamchainsaw
    在 GitHub 上查看↗3,446
  • sleuthkit/autopsysleuthkit 的头像

    sleuthkit/autopsy

    3,015在 GitHub 上查看↗

    Autopsy is a digital forensic analysis platform and evidence management suite used to process disk images and file systems. It provides a graphical interface for performing deep forensic examinations of computer hard drives to identify and extract digital artifacts for investigations. The platform is built as a Java-based forensic framework that integrates native libraries to perform direct disk image analysis. It utilizes a modular architecture, allowing for the extension of data ingestion and report generation through the use of plugins. The system manages digital evidence within a central

    Javaforensicsjava
    在 GitHub 上查看↗3,015
查看 Emergency Response Notes 的所有 30 个替代方案→

常见问题解答

bypass007/emergency-response-notes 是做什么的?

Emergency-Response-Notes 是一套用于执行取证分析、事件响应、入侵识别和恶意软件修复的技术参考文档和手册。它作为一个事件响应知识库和入侵分析框架,帮助识别安全攻击期间使用的 Web shell、隐藏后门和持久化机制。

bypass007/emergency-response-notes 的主要功能有哪些?

bypass007/emergency-response-notes 的主要功能包括:Forensic Analysis Playbooks, Digital Forensics and Analysis, Forensic Investigation Playbooks, Response Case Studies, Persistence Mechanisms, Intrusion Analysis Frameworks, Intrusion Detection Workflows, Malware Removal。

bypass007/emergency-response-notes 有哪些开源替代品?

bypass007/emergency-response-notes 的开源替代品包括: neo23x0/loki — Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a… google/grr — GRR is a distributed incident response platform and asynchronous forensic task orchestrator. It functions as a remote… withsecurelabs/chainsaw — Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It… sleuthkit/autopsy — Autopsy is a digital forensic analysis platform and evidence management suite used to process disk images and file… beurtschipper/depix — Depix is a pixelation recovery tool and digital forensics utility designed to reconstruct plaintext from pixelated… dominicbreuker/stego-toolkit — This project is a steganography analysis toolkit and digital forensics suite designed to detect, extract, and embed…