Awesome Cybersecurity Blue Team
Section: Threat hunting · All in one PowerShell-based platform to perform live hard disk forensic analysis.
Entry
Appears in 6 awesome lists
All in one PowerShell-based platform to perform live hard disk forensic analysis.
Section: Threat hunting · All in one PowerShell-based platform to perform live hard disk forensic analysis.
Section: 威胁狩猎 · 基于PowerShell,用于实时硬盘取证分析的多合一平台
Section: Windows Evidence Collection · Live disk forensics platform, using PowerShell.
Section: Security · Popular live disk forensics platform for windows.
Section: Power Forensic
Section: Frameworks · PowerForensics is a framework for live disk forensic analysis
Fibratus is a tool for exploration and tracing of the Windows kernel. It is able to capture the most of the Windows kernel activity - process/thread creation and termination, file system I/O, registry, network activity, DLL loading/unloading and much more. Fibratus has a very simple CLI which…
Incident response framework focused on remote live forensics. It consists of a python agent (client) that is installed on target systems, and a python server infrastructure that can manage and talk to the agent. Besides the included Python API client, PowerGRR provides an API client library in…
Multi-platform tool for triaging suspected IOCs on many endpoints simultaneously and that integrates with antivirus consoles.
Provides host investigative capabilities to users to find signs of malicious activity through memory and file analysis, and the development of a threat assessment profile.
All-in-one Free Software threat hunting stack based on Elasticsearch, Logstash, Kafka, and Kibana with various built-in integrations for analytics including Jupyter Notebook.
A suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows
Free IR scanner for scanning endpoint with yara rules and other indicators(IOCs).
PSRecon gathers data from a remote Windows host using PowerShell (v2 or later), organizes the data into folders, hashes all extracted data, hashes PowerShell and various system properties, and sends the data off to the security team. The data can be pushed to a share, sent over email, or retained…