dfir
Here are 767 public repositories matching this topic...
Language:All
Sort:Most stars
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
- Updated
Oct 16, 2025 - Shell
A curated list of tools for incident response
- Updated
Jul 18, 2024
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
- Updated
Oct 2, 2025 - XSLT
Automate the creation of a lab environment complete with security tooling and logging best practices
- Updated
Jul 6, 2024 - HTML
⭐️ A curated list of awesome forensic analysis tools and resources
- Updated
Oct 2, 2025
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
- Updated
Feb 15, 2024 - Python
IntelOwl: manage your Threat Intelligence at scale
- Updated
Nov 6, 2025 - Python
TheHive: a Scalable, Open Source and Free Security Incident Response Platform
- Updated
Jul 25, 2025 - Scala
Collaborative forensic timeline analysis
- Updated
Nov 5, 2025 - Python
Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
- Updated
Apr 16, 2021
Investigate malicious Windows logon by visualizing and analyzing Windows event log
- Updated
Oct 19, 2025 - Python
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
- Updated
Nov 5, 2025 - Rust
A repository of sysmon configuration modules
- Updated
Aug 21, 2024 - PowerShell
YARA signature and IOC database for my scanners and tools
- Updated
Nov 3, 2025 - YARA
Windows Events Attack Samples
- Updated
Jan 24, 2023 - HTML
Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
- Updated
Jan 4, 2024 - Python
A list of cyber-chef recipes and curated links
- Updated
Jun 14, 2024
Improve this page
Add a description, image, and links to thedfir topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with thedfir topic, visit your repo's landing page and select "manage topics."