DFIRJoe's starred repositories
fastfinder
Incident Response - Fast suspicious file finder
Sentinel-One-STAR-Rules-Threat-Hunts
SentinelOne STAR Rules
defender-detectionhistory-parser
A parser of Windows Defender's DetectionHistory forensic artifact, containing substantial info about quarantined files and executables.
OpenSearch-Dashboards
📊 Open source visualization dashboards for OpenSearch.
Get-MiniTimeline
Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE
velociraptor
Digging Deeper....
Detection-Ideas-Rules
Detection Ideas & Rules repository.
DetectionLab
Automate the creation of a lab environment complete with security tooling and logging best practices
AllthingsTimesketch
This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.
timesketch
Collaborative forensic timeline analysis