Commit Graph

301 Commits

Author SHA1 Message Date
V
fe9ee8ce86
Added Cahinsaw log analysis tool.
Added Cahinsaw log analysis tool.
2021-12-30 14:06:24 +00:00
Jonas Plum
28cf4dc416
Add Catalyst
Added Catalyst, a SOAR and incident management system
2021-12-27 19:19:00 +01:00
V
aa19f183ce
Added Orochi
Added Orochi, a framework for memory dump analysis.
2021-12-27 12:11:47 +00:00
Mathias Stuhlmacher
3596e78069 added Awesome Event IDs 2021-12-21 21:06:39 +01:00
echin20
74641b542e
Update README.md
Fixing another format issue.
2021-10-29 08:40:36 -04:00
echin20
19361b3bff
Update README.md
Fixing format mistake.
2021-10-29 08:39:31 -04:00
echin20
07dd5d46f4
Update README.md
Adding ESF Playground to the OSX Evidence Collection section
2021-10-29 08:37:25 -04:00
Mathias Stuhlmacher
5c27f154b4 fixed typos 2021-10-11 20:29:40 +02:00
Mathias Stuhlmacher
8031dec238 added MFT browser 2021-10-11 19:04:58 +02:00
Mathias Stuhlmacher
f7d79d80d8 removed beagle 2021-09-22 20:17:50 +02:00
Mathias Stuhlmacher
9bb926c970 Merge https://github.com/meirwah/awesome-incident-response into original_master 2021-09-22 18:59:58 +02:00
Andrew Rathbun
c480b7502c
Update README.md
Minor fix
2021-09-15 11:54:16 -04:00
Andrew Rathbun
5bc56db6bb Update README.md 2021-09-15 11:28:32 -04:00
Andrew Rathbun
d2a8d20757
Merge branch 'meirwah:master' into master 2021-09-15 08:39:29 -04:00
Andrew Rathbun
0ea1d71f3f
Update README.md 2021-09-15 07:46:59 -04:00
Meir Wahnon
9d25729b04
Merge pull request #172 from lizardlabs/patch-1
Log Parser Lizard na Event Log Observer are added to the list
2021-09-15 09:56:56 +03:00
Andrew Rathbun
66a98b7cdf update README.md 2021-09-14 22:01:24 -04:00
Andrew Rathbun
0edb63700e update README.md 2021-09-14 21:57:09 -04:00
Mathias Stuhlmacher
04dbc3b591 fixed table of contents 2021-07-26 08:58:11 +02:00
Mathias Stuhlmacher
4d15b16088 Merge https://github.com/meirwah/awesome-incident-response into original_master 2021-07-26 08:45:10 +02:00
Mathias Stuhlmacher
7ffb3a998d changed according to PR comments 2021-07-26 08:38:32 +02:00
Pedro Cunha
650eb9abcf Book: Intelligence-Driven Incident Response 2021-07-25 18:07:58 +01:00
Pedro Cunha
06dc2aa152 Book: Intelligence-Driven Incident Response 2021-07-25 18:02:33 +01:00
Pedro Cunha
4401aab8fa Book: Intelligence-Driven Incident Response 2021-07-25 13:18:24 +01:00
Lizard Labs Software
15bd5b7fb2
Update README.md 2021-07-10 01:06:36 +02:00
Paul Masek
fc879a1821
Added "AWS Incident Response Runbook Samples" 2021-06-24 10:30:35 -04:00
Mathias Stuhlmacher
10fced5d21 added book 2021-06-15 23:33:13 +02:00
Mathias Stuhlmacher
7c85f1ee07 added and updated tools and repos 2021-06-15 23:16:49 +02:00
Mathias Stuhlmacher
aaa11a328e changed DFIRTrack link to reflect move to an organization 2021-06-09 20:11:48 +02:00
V
1635b0a0de
Added some new resources. 2021-06-01 19:09:39 +02:00
V
9740c6ec4f
Added a note for Rekall
Rekall is not maintained anymore and the author archived the repo.
2021-06-01 18:56:40 +02:00
V
962658bc37
Added books in sorted order 2021-06-01 18:48:51 +02:00
V
f9cc1eb5d2
Added new books 2021-06-01 18:43:22 +02:00
Marco
a594e7e878
Update README.md
Adding new SandBox Tool
2021-05-17 09:34:28 +02:00
Meir Wahnon
e6e230551c
Merge pull request #154 from spellanser/patch-1
add AVML memory acquisition tool
2021-03-22 08:44:10 +02:00
Thiago Canozzo Lahr
6b242418a7 upd: UAC tool description updated
Signed-off-by: Thiago Canozzo Lahr <tclahr@br.ibm.com>
2021-02-22 22:58:15 -03:00
Ahmed Elshaer
e7d0d54c68
replacing kolide with fleetdm
positioned in the correct order
2021-01-25 10:21:17 +01:00
Ahmed Elshaer
4bbc34149a
replacing kolide with fleetdm 2021-01-25 09:40:16 +01:00
RDxR10
3cea504804
Fixed some typos :) 2020-10-31 00:28:37 +05:30
Explie
05a18e7b0f
Resolving PR comments
Resolving Review https://github.com/meirwah/awesome-incident-response/pull/158
2020-10-28 16:41:10 +01:00
Explie
cca8e193cc
Updating IOCFinder description, no longer maintained 2020-10-28 13:56:26 +01:00
Explie
ed8a880c4e
Removing TRIAGE-IR, old and unavailable
Source code unavailable. Last deployment Nov 9, 2012
2020-10-28 13:54:15 +01:00
Explie
f925159070
Updating dead RegRipper Link 2020-10-28 13:52:14 +01:00
Explie
6a69cc8d88
Removing Fidelis TS, no longer available 2020-10-28 13:51:13 +01:00
Explie
cc25ebae59
Removing FECT, no longer maintained nor running
Development status
FECT is no longer maintained
2020-10-28 13:49:54 +01:00
Explie
aa6a76b2fe
Removing binforray, no longer available
Replaced by https://ericzimmerman.github.io/
2020-10-28 13:48:58 +01:00
Explie
98b2496fc9
Fixing dead Cuckoo SB Link
Fixing dead Cuckoo SB Link
2020-10-28 13:44:36 +01:00
Explie
892d4a694c
Updating CAPE with newer Version CAPEv2
Updating CAPE with newer Version CAPEv2
2020-10-28 13:44:01 +01:00
Explie
b5cbb95ece
Replacing User Mode Process Dumper with ProcDump
The Microsoft User Mode Process Dumper is no longer available. Alternate Sysinternals Tool would be ProcDump
2020-10-28 13:43:10 +01:00
Explie
22b3932946
Updating KnockKnock Link, no longer open source
Updating KnockKnock Link, no longer open source
2020-10-28 13:40:46 +01:00