A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.
-
Updated
Oct 4, 2025 - Python
A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.
MacOS forensic acquisition made simple
A repo that aims to centralize a current, running list of relevant parsers/tools for known DFIR artifacts
Casting light on shadow cloud deployments. Detect exposure of resources deployed in AWS.
Automatically create iSCSI targets for all drives except for a boot device
A tool for fetching DFIR and other GitHub tools.
Vault of Windows Registry forensic artifacts
macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR
Cryptocurrency Discovery and Triage Tool - Identify multiple cryptocurrency addresses and transactions from various wallet applications!
Outil de triage automatisé de différents types de collectes d'artefacts.
A collection of PowerShell scripts for analyzing macOS Forensic Artifacts
Yerel ağlarda anomaly detection, saldırı tespiti ve adli bilişim analizi yapan tek Pythontkinter tabanlı açık kaynak araç. Özelleştirilebilir imza veritabanıyla Türkiye odaklı tehditleri yakalar!
Bu repository, siber güvenlik uzmanları, SOC ekipleri ve tehdit avcıları için profesyonel YARA kurallarını bir araya getiren canlı bir bilgi havuzudur. Her kural derinlemesine malware analizi ve reverse engineering çalışmaları sonucunda geliştirilmiştir.
AWMFA - Automated Windows Memory Forensics Analysis. Python automation framework for Volatility 2 that streamlines memory analysis. Features: automated plugin execution with threading, intelligent threat detection using 28+ heuristics, no deep Windows internals knowledge required, multi-format reports (TXT/HTML/PDF).
A deployment and testing platform for Velociraptor's client artifacts
A forensic command-line tool for deep analyzing PDF files
Convert Kape Files to DFIR-ORC configurations
OpenRelik ertools worker
Linux Forensic Collector, Quick & Thorough.
Add a description, image, and links to the dfir-tools topic page so that developers can more easily learn about it.
To associate your repository with the dfir-tools topic, visit your repo's landing page and select "manage topics."