DFIRTrack - The Incident Response Tracking Application
-
Updated
Sep 4, 2024 - Python
DFIRTrack - The Incident Response Tracking Application
AWS CloudSaga - Simulate security events in AWS
A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.
AHA is an incident management & communication framework to provide real-time alert customers when there are active AWS event(s). For customers with AWS Organizations, customers can get aggregated active account level events of all the accounts in the Organization. Customers not using AWS Organizations still benefit alerting at the account level.
A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️
Forensic toolkit for iOS sysdiagnose feature
An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.
The DNA test for websites
CLI program for automating the setup, configuration, and use of cybersecurity solutions
Unpage is the open source framework for building SRE agents with infrastructure context and secure access to any dev tool.
Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.
CLI for selecting and back-testing CloudWatch alarm configuration
Cortex-Analyzers Modified - SecTeam/CERT/SOC Security orchestration tools on steroids
AWMFA - Automated Windows Memory Forensics Analysis. Python automation framework for Volatility 2 that streamlines memory analysis. Features: automated plugin execution with threading, intelligent threat detection using 28+ heuristics, no deep Windows internals knowledge required, multi-format reports (TXT/HTML/PDF).
systeminfo command for offline system images
Incident Response in AWS with Alexa
forensics.py is a remote forensic data collection tool that gathers system information, logs, and other relevant data from one or multiple remote hosts.
A CLI tool for generating observability queries to assist incident responders during incident investigation.
QRadar to Redmine(as Ticketing System) Integration with API CALLS written in Python
Scope is an open source cloud forensic tool to rapidly analyse logs, detect suspicious activity and identify malicious resources. Scope supports Amazon Web Services (AWS), Google Cloud Platform (GCP) and Microsoft Azure.
Add a description, image, and links to the incident-response-tooling topic page so that developers can more easily learn about it.
To associate your repository with the incident-response-tooling topic, visit your repo's landing page and select "manage topics."