Showing 36 of 37 projects
A curated list of tools and resources for digital forensics and incident response (DFIR) teams.
A curated list of tools and resources for digital forensics and incident response (DFIR) teams.
A curated list of awesome free forensic analysis tools, resources, and learning materials for digital investigators.
A curated list of awesome free (mostly open source) forensic analysis tools and resources for digital investigations.
A community-driven open-source project that structures threat hunting workflows using MITRE ATT&CK, Jupyter notebooks, and AI-augmented planning.
A simple IOC and YARA scanner for detecting malware and security threats via file names, hashes, YARA rules, and C2 connections.
A fast, standalone tool for rapid threat hunting and forensic analysis of Windows event logs and other forensic artefacts.
An open-source tool for collaborative forensic timeline analysis, enabling teams to organize, annotate, and investigate timelines together.
A Sigma-based threat hunting and fast forensics timeline generator for Windows event logs, written in Rust.
A security tool that visualizes and analyzes Windows Active Directory event logs to investigate malicious logon activity.
A Linux distribution for threat hunting, enterprise security monitoring, and log management.
A modular repository of Sysmon configuration modules for customizable endpoint detection and logging.
A collection of 200 Windows EVTX event log samples mapped to MITRE ATT&CK techniques for detection testing and threat hunting.
A forensics intelligence platform that bridges CTI and DFIR by storing threat intelligence and enabling bulk observable searches and threat-focused analysis.
A repository of publicly-available reports and blogs on APT (Advanced Persistent Threat) campaigns, activity, and software, organized by year.
A collection of ready-to-use KQL queries for threat hunting, detection, and analytics in Microsoft Defender for Endpoint and Azure Sentinel.
A browser forensics tool for analyzing web artifacts from Google Chrome and other Chromium-based browsers.
A community-sourced, machine-readable knowledge base of digital forensic artifacts for use in forensic tools and investigations.
A malware communication analyzer that visualizes network traffic and cross-references it with known malware sources.
A digital forensics and incident response framework for unified analysis of forensic artifacts across disk formats, filesystems, and operating systems.
A Python-based DFIR framework for extracting forensic artifacts from macOS and iOS disk images or live systems.
An extendable Python tool to extract and aggregate Indicators of Compromise (IOCs) from various threat intelligence feeds.
An extendable Python tool to extract and aggregate Indicators of Compromise (IOCs) from various threat intelligence feeds.
A digital forensics investigation platform for parsing, searching, visualizing evidence, and enabling team collaboration.
A curated collection of Event ID resources for digital forensics and incident response professionals.
A system-focused web application for tracking systems, tasks, and artifacts during major digital forensics and incident response (DFIR) investigations.
A self-hosted incident response platform that automates alert handling and ticket management for security teams.
An open-source platform for collecting, processing, and analyzing forensic artifacts from macOS, Windows, and Linux systems.
A forensic artifact parsing tool that quickly analyzes disk images and extracted artifacts from Windows, Linux, macOS, and Android devices.
A customizable single-binary agent for collecting forensic artifacts from Windows, macOS, and Linux systems.
A lightweight incident response tool for rapid suspicious file discovery during threat hunting and forensic triage.
A command-line tool for parsing, searching, and analyzing Windows Registry hives with batch processing and forensic capabilities.
A unified console for digital forensics and incident response (DFIR) built on the Viper Framework.
A unified console for digital forensics and incident response built on the Viper Framework.
A PowerShell-based live response and forensic collection tool for targeted incident response on Windows systems.
A PowerShell tool for auditing and configuring Windows event log settings to improve security visibility and detection capabilities.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.