Skip to content

Entry

GRR Rapid Response

Appears in 6 awesome lists

Incident response framework focused on remote live forensics. It consists of a python agent (client) that is installed on target systems, and a python server infrastructure that can manage and talk to the agent. Besides the included Python API client, PowerGRR provides an API client library in…

Open github.comgoogle/grr

Found in these lists

Awesome Cybersecurity Blue Team

Section: Threat hunting · Incident response framework focused on remote live forensics consisting of a Python agent installed on assets and Python-based server infrastructure enabling analysts to quickly triage attacks and perform analysis remotely.

StaleScore 53

Awesome Cybersecurity Blue Team - CN

Section: 威胁狩猎 · 一个专注于远程实时取证的事件响应框架,该组件由安装在资产上的Python代理和基于Python的服务器组成基础结构,使分析师能够快速分类攻击并进行远程分析

StaleScore 47

awesome-game-security

Section: Anti Cheat · [remote live forensics]

FreshScore 88

Awesome Incident Response

Section: All-In-One Tools · Incident response framework focused on remote live forensics. It consists of a python agent (client) that is installed on target systems, and a python server infrastructure that can manage and talk to the agent. Besides the included Python API client, PowerGRR provides an API client library in…

ActiveScore 82

Awesome Security

Section: Forensics · GRR Rapid Response is an incident response framework focused on remote live forensics.

SlowScore 70

Forensics Tools

Section: Live forensics · GRR Rapid Response: remote live forensics for incident response

ActiveScore 77

Volatility

Python based memory extraction and analysis framework.

In 8 listsDetails

Fibratus

Fibratus is a tool for exploration and tracing of the Windows kernel. It is able to capture the most of the Windows kernel activity - process/thread creation and termination, file system I/O, registry, network activity, DLL loading/unloading and much more. Fibratus has a very simple CLI which…

In 8 listsDetails

wazuh/wazuh

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of monitoring file system changes, system calls and inventory changes.

In 7 listsDetails

PowerForensics

All in one PowerShell-based platform to perform live hard disk forensic analysis.

In 6 listsDetails

CTRE

A Compile time PCRE (almost) compatible regular expression matcher. [MIT]

In 4 listsDetails

a0rtega/pafish

Pafish is a testing tool that uses different techniques to detect virtual machines and malware analysis environments in the same way that malware families do (archived)

In 4 listsDetails

Amber

Position-independent(reflective) PE loader that enables in-memory execution of native PE files(EXE, DLL, SYS).

In 4 listsDetails

lazagne

An open source application used to retrieve lots of passwords stored on a local computer.

In 4 listsDetails