dfir-automation topic

List dfir-automation repositories

BlueCloud

122
Stars
30
Forks
Watchers

Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.

PurpleCloud

483
Stars
85
Forks
Watchers

A little tool to play with Azure Identity - Azure Active Directory lab creation tool

epagneul

225
Stars
33
Forks
Watchers

Graph Visualization for windows event logs

DetectionLab

4.5k
Stars
972
Forks
Watchers

Automate the creation of a lab environment complete with security tooling and logging best practices

rip_raw

132
Stars
16
Forks
Watchers

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

hashlookup-forensic-analyser

117
Stars
12
Forks
Watchers

Analyse a forensic target (such as a directory) to find and report files found and not found from CIRCL hashlookup public service - https://circl.lu/services/hashlookup/

SimpleImager

30
Stars
4
Forks
Watchers

Simple Imager has been created for performing live acquisition of Windows based systems in a forensically sound manner

varc

234
Stars
12
Forks
Watchers

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use when investigating a security incident.

hashlookup-server

39
Stars
7
Forks
Watchers

Fast lookup server for NSRL and other hash database used in digital forensic

Velociraptor_Azure

19
Stars
4
Forks
Watchers

A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.