cyberstars
cyberstars / purpose / forensics

Outils pour forensics

Incident response and evidence collection.

88 tools indexed

Runtime security for containers.

MonitorCloudEndpoints
C++Apache-2.0

Adversary tradecraft detection on Windows.

MonitorAnalyzeEndpoints
GoApache-2.0

Osquery-powered device management.

MonitorHardenEndpoints
GoMIT

NSA's open-source reverse engineering suite.

AnalyzeBinaries
JavaApache-2.0

Recover Go symbol info from binaries.

AnalyzeBinaries
GoMIT

Open log management.

MonitorAnalyzeNetworksEndpoints
JavaSSPL-1.0

HELK

The Hunting ELK stack.

MonitorAnalyzeEndpointsNetworks
Jupyter NotebookGPL-3.0

Windows event log threat hunter.

AnalyzeMonitorEndpoints
RustAGPL-3.0

Chrome/Chromium browser forensics.

AnalyzeEndpoints
PythonApache-2.0

IPED

Open-source digital forensics processor.

AnalyzeEndpointsBinaries
JavaEPL-2.0

Hex editor for reverse engineers.

AnalyzeBinaries
C++GPL-2.0

Manage threat intel at scale.

AnalyzeAutomateNetworksEndpoints
PythonAGPL-3.0

CPU-based password cracker.

CrackEndpointsActive Directory
CGPL-2.0

Visualize Windows logon events.

AnalyzeMonitorActive DirectoryEndpoints
PythonMIT

Loki

Simple IOC and YARA scanner.

ScanAnalyzeEndpoints
PythonGPL-3.0

MISP

Threat intelligence sharing platform.

AutomateAnalyzeNetworksEndpoints
PHPAGPL-3.0

Microsoft Threat Intelligence in Python.

AnalyzeAutomateCloudEndpoints
PythonMIT

Username OSINT across 3000+ sites.

ReconWeb apps
PythonMIT

Graph-based OSINT and link analysis.

ReconAnalyzeWeb appsNetworks
JavaProprietary

Malicious-traffic detection system.

MonitorInterceptNetworks
PythonMIT

Open-source security data lake on AWS.

MonitorAnalyzeCloudNetworks
RustApache-2.0

Memory forensics as a filesystem.

AnalyzeEndpointsBinaries
CAGPL-3.0

Open cyber threat intelligence platform.

AnalyzeAutomateNetworksEndpoints
TypeScriptApache-2.0

Decentralized, modular honeypot.

MonitorNetworksEndpoints
PythonBSD-3-Clause