unforensicate's starred repositories

v2ray-core

A platform for building proxies to bypass network restrictions.

dnSpy

.NET debugger and assembly editor

Language:C#Stargazers:26425Issues:992Issues:0

atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

sigma

Main Sigma Rule Repository

Language:PythonLicense:NOASSERTIONStargazers:8198Issues:343Issues:598

Responder

Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authentication.

Language:PythonLicense:GPL-3.0Stargazers:5380Issues:144Issues:182

GOAD

game of active directory

Language:PowerShellLicense:GPL-3.0Stargazers:5111Issues:78Issues:187

ThreatHunter-Playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

Language:PythonLicense:MITStargazers:3988Issues:371Issues:33

awesome-threat-detection

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

APTnotes

Various public documents, whitepapers and articles about APT campaigns

Active-Directory-Exploitation-Cheat-Sheet

A cheat sheet that contains common enumeration and attack methods for Windows Active Directory.

Language:PowerShellLicense:MITStargazers:2456Issues:76Issues:2

Microsoft-365-Defender-Hunting-Queries

Sample queries for Advanced hunting in Microsoft 365 Defender

Language:Jupyter NotebookLicense:MITStargazers:1920Issues:197Issues:36

osxcollector

A forensic evidence collection & analysis toolkit for OS X

Language:PythonLicense:NOASSERTIONStargazers:1871Issues:125Issues:75

plaso

Super timeline all the things

Language:PythonLicense:Apache-2.0Stargazers:1707Issues:92Issues:2037

Sentinel-Queries

Collection of KQL queries

log4j-affected-db

A community sourced list of log4j-affected software

Language:ShellLicense:CC0-1.0Stargazers:1116Issues:85Issues:154

LOLDrivers

Living Off The Land Drivers

Language:YARALicense:Apache-2.0Stargazers:992Issues:28Issues:60

FalconFriday

Hunting queries and detections

LinuxForensics

Everything related to Linux Forensics

srum-dump

A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.

Language:PythonLicense:GPL-3.0Stargazers:592Issues:38Issues:30

awesome_Threat-Hunting

A curated list of the most important and useful resources about Threat Detection,Hunting and Intelligence.

automactc

AutoMacTC: Automated Mac Forensic Triage Collector

Language:PythonLicense:NOASSERTIONStargazers:523Issues:72Issues:9

MalSeclogon

A little tool to play with the Seclogon service

Language:CLicense:GPL-3.0Stargazers:301Issues:6Issues:1

lmg

Script for automating Linux memory capture and analysis

TrueTree

A command line tool for pstree-like output on macOS with additional pid capturing capabilities

Language:SwiftLicense:NOASSERTIONStargazers:242Issues:13Issues:4

crowdstrike-falcon-queries

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

RECmd

Command line access to the Registry

Language:RebolLicense:MITStargazers:126Issues:19Issues:14

ese-analyst

This is a set of tools for doing forensics analysis on Microsoft ESE databases.

Awesome-Regex-Resources

A curated list of Regex Resources. Inspired by other awesome stuff

EventTranscript.db-Research

A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.

License:MITStargazers:38Issues:3Issues:0