The project is a part of the Performing remote live response on organizational environment thesis made for CYBERDI project.
-
Updated
Apr 14, 2020 - Shell
The project is a part of the Performing remote live response on organizational environment thesis made for CYBERDI project.
The ultimate solution for remotely deploying Crowdstrike sensors quickly and discreetly on any other EDR platform.
An alternative to "wazuh-docker" with CI/CD-built images for amd64 and arm64, published on Docker Hub.
Digital Forensics and Incident Response
🏴☠️ BST is an ever-evolving collection of 🛠 tools to help in security and administration tasks 😉
NginxHunter - Powerful Nginx log analyzer and security hunter.
Deploy a Wazuh cluster with a hardened (prod. ready) stack on Kubernetes.
The scrip will help you to find some values info for the user that you need as DFIR
j3rmbadger blog
Triage scripts for Intel-based Macs
A collection of my coursework, including network and malware behavior analysis as well as live incident response.
Break-In Analyzer - A script that analyze auth.log, secure, utmp/wtmp for possible SSH break-in attempts
An All-in-One script designed to automate Incident Reponse investigations on HDD images and MEM files while using Kali Linux.
Incident Response Linux Investigation Tool: A concise, efficient script for system administrators and IT professionals, perfect for Linux system diagnostics. It gathers essential data on user accounts, processes, logs, and network configurations, ensuring secure and effective incident response and troubleshooting.
Forensic Linux VM for Apple Silicon, ARM64 and x86-64 compatible platforms
TriageX - Linux Triage Tool Is a BASH shell script designed to collect evidences in an incident with Linux machines. The script uses native Linux commands to run.
Scripts used during Incident response security competition
A dockerized log server, that has plug and play capabilities.
Incident Forensic Response In Terminal script for linux
Add a description, image, and links to the incident-response topic page so that developers can more easily learn about it.
To associate your repository with the incident-response topic, visit your repo's landing page and select "manage topics."