dfir-automation
Here are 85 public repositories matching this topic...
Language:All
Sort:Most stars
Automate the creation of a lab environment complete with security tooling and logging best practices
- Updated
Jul 6, 2024 - HTML
MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
- Updated
Aug 17, 2025 - PowerShell
A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog:https://medium.com/@iknowjason/sentinel-for-purple-teaming-183b7df7a2f4
- Updated
Mar 21, 2025 - Python
Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use when investigating a security incident.
- Updated
Nov 18, 2024 - Python
A curated list of tools for incident response. With repository stars⭐ and forks🍴
- Updated
Dec 16, 2025
Graph Visualization for windows event logs
- Updated
Jan 15, 2025 - Python
Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.
- Updated
Nov 2, 2022 - HTML
Rip Raw is a small tool to analyse the memory of compromised Linux systems.
- Updated
Jan 31, 2022 - Python
Analyse a forensic target (such as a directory) to find and report files found and not found from CIRCL hashlookup public service -https://circl.lu/services/hashlookup/
- Updated
Sep 24, 2023 - Python
Fast lookup server for NSRL and other hash database used in digital forensic
- Updated
Jun 16, 2022 - Python
unix_collector is a Live Response collection script for Incident Response on UNIX-like systems using native binaries. Supports AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
- Updated
Jun 10, 2025 - Shell
Pipeline that allows sending forensic artifacts to OpenRelik for automatic processing
- Updated
Nov 24, 2025 - Python
MAES: M365 Analyzer & Extractor Suite Po
- Updated
Dec 2, 2025 - JavaScript
Simple Imager has been created for performing live acquisition of Windows based systems in a forensically sound manner
- Updated
Oct 28, 2025 - Batchfile
Automatically create iSCSI targets for all drives except for a boot device
- Updated
May 23, 2025 - Python
A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.
- Updated
Apr 16, 2021 - HCL
Easy automated vagrant provisioning of Windows 10 with flarevm tools installed for Digital Forensics and Malware Analysis Lab.
- Updated
May 29, 2022 - HCL
Toolset to analyze disks encrypted with McAFee FDE technology
- Updated
Mar 11, 2021 - Python
Sabonis, a Digital Forensics and Incident Response pivoting tool
- Updated
Mar 3, 2022 - Python
Improve this page
Add a description, image, and links to thedfir-automation topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with thedfir-automation topic, visit your repo's landing page and select "manage topics."