ir-rescue

Forensic scanner

A tool for comprehensively collecting host forensic data during incident response and analysis.

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

GitHub

466 stars
44 watching
94 forks
Language: Batchfile
last commit: over 5 years ago
Linked from 3 awesome lists

bashbatchcybersecuritydfirforensicsincident-responsemalwarenirsoftsysinternalsunixwindows

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
diogo-fernan/domfindA tool to find identical domain names with SOA DNS records under different TLDs24
travisfoley/dfirtriageA digital forensic tool designed to gather and analyze data from Windows-based systems in incident response scenarios.335
dfir-iris/iris-webA collaborative platform for incident responders to share technical details during investigations1,091
eliasgranderubio/dagdaA tool to analyze and monitor Docker images and containers for security threats1,164
codeyourweb/fastfinderTools for detecting suspicious files and directories on Windows and Linux endpoints.234
dissectmalware/officeforensictoolsA Python-based collection of tools for gathering forensic information from Office documents26
teamdfir/siftA suite of tools and images for building and managing digital forensics environments on AWS494
securityjoes/forensicminerAutomates evidence collection and analysis from Windows machines using PowerShell.149
jfarley248/meatA toolkit for acquiring and analyzing evidence from iOS devices140
netflix-skunkworks/diffyAn incident response tool that helps digital forensics teams analyze and prioritize suspicious hosts in cloud environments635
flo354/iosforensicA tool to aid in forensic analysis of iOS devices63
joeavanzato/trawlerA PowerShell script designed to help Incident Responders discover potential indicators of compromise on Windows hosts by scanning for various persistence techniques.310
msuhanov/dfir_ntfsA digital forensics tool for parsing and analyzing NTFS/FAT file systems.196
ydkhatri/mac_aptA digital forensics tool for analyzing macOS and iOS systems790
anssi-fr/dfir4vsphereA PowerShell module for collecting logs and forensics data from VMware vSphere environments.143