Skip to content
View mattreduce's full-sized avatar
🏎️
🏎️

Organizations

@hashicorp @hashivim @MythicAgents @srcmtd

Block or report mattreduce

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Please don't include any personal information such as legal names or email addresses. Maximum 100 characters, markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Stars

🔬 dfir

Digital Forensic & Incident Response
46 repositories

Symbol hash for ELF files

Python 105 15 Updated Feb 9, 2022
TypeScript 443 23 Updated May 24, 2023

Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.

Python 242 22 Updated Dec 27, 2022

A tool to help forensicate offline docker acquisitions

Python 533 46 Updated Oct 4, 2024

A framework for orchestrating forensic collection, processing and data export

Python 303 71 Updated Jan 14, 2025

Super timeline all the things

Python 1,758 360 Updated Dec 27, 2024

Python library to carry out DFIR analysis on the Cloud

Python 468 87 Updated Dec 15, 2024

Automation and Scaling of Digital Forensics Tools

Python 755 165 Updated Jan 2, 2025

Linux audit userspace repository

C 612 213 Updated Jan 14, 2025

The Threat Hunting In Rapid Iterations (THIRI) Jupyter notebook is designed as a research aide to let you rapidly prototype threat hunting rules.

Python 154 14 Updated Apr 25, 2022

Repository resource for threat hunter

158 34 Updated Sep 14, 2018

Python 3 library to build YARA rules.

Python 13 2 Updated Oct 24, 2021

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

Python 1,717 212 Updated Jan 4, 2024

A happy place for detection engineers, purple teamers and threat hunters focusing on macOS.

HTML 21 2 Updated Jun 8, 2022

A Self-Contained Open-Source Cyberattack Experimentation Testbed

Python 37 10 Updated Jan 7, 2025

Web based Manager for Yara Rules

Python 57 22 Updated Mar 9, 2020

🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system

Go 274 21 Updated Oct 20, 2024

Make a cascading timeline from markdown-like text. Supports simple American/European date styles, ISO8601, images, links, locations, and more.

HTML 4,335 141 Updated Dec 11, 2023

Remote Memory Acquisition Tool

Python 245 48 Updated Sep 22, 2020

Elastic Security detection content for Endpoint

YARA 1,082 121 Updated Jan 13, 2025

Digging Deeper....

Go 3,049 501 Updated Jan 14, 2025

Linux Baseline and Forensic Triage Tool - BETA

Shell 52 6 Updated Sep 8, 2022

Go symbol recovery tool

Go 642 69 Updated Oct 19, 2024

Dissect is a digital forensics & incident response framework and toolset that allows you to quickly access and analyse forensic artefacts from various disk and file formats, developed by Fox-IT (pa…

944 69 Updated Dec 10, 2024

Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...

1,055 181 Updated Sep 4, 2024

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Python 173 25 Updated Sep 23, 2024

DC3 Malware Configuration Parser (DC3-MWCP) is a framework for parsing configuration information from malware. The information extracted from malware includes items such as addresses, passwords, fi…

Python 305 56 Updated Jun 6, 2024

A standard for reducing log volume without sacrificing analytical capability

198 17 Updated Jul 26, 2023