IRCoreForensicFramework

Incident responder tool

Automates incident response actions to gather and process forensic artefacts from remote systems

Powershell / C# based cross platform forensic framework based for live incident response

GitHub

22 stars
5 watching
5 forks
Language: PowerShell
last commit: over 4 years ago

Related projects:

Repository Description Stars
davehull/kansa A modular incident response framework in Powershell 1,559
ajmartel/irtriage Automated incident response tool for collecting critical system information during forensic analysis of Windows systems. 130
atc-project/atc-react A knowledge base of actionable Incident Response techniques 613
certsocietegenerale/irm Operational guidelines and best practices for handling various types of security incidents 978
invoke-ir/powerforensics A C#-based framework for analyzing and investigating hard drive forensic data 1,385
cyberdefenseinstitute/cdir A tool designed to collect data from Windows systems during an incident response 154
demisto/cops Standardized framework for creating and sharing incident response processes in a shared language 150
tap-ir/tapir An incident response framework with multi-user support, providing plugins for file analysis and a REST API for data access 44
certsocietegenerale/fir A cybersecurity incident management platform for tracking and managing security incidents in real-time. 1,734
cisagov/untitledgoosetool A tool for investigating and responding to security incidents in cloud-based Microsoft environments. 913
dfir-iris/iris-web A collaborative incident response platform allowing technical details to be shared during investigations 1,079
pjrinaldi/wombatforensics A multi-threaded GUI forensic analysis tool for Linux 47
cyb3rfox/aurora-incident-response A tool designed to help incident responders track and manage findings and tasks during security investigations. 766
opensourcesec/cirtkit A comprehensive toolset for digital forensics and incident response analysis using Python 142
securityjoes/forensicminer Automates evidence collection and analysis from Windows machines using PowerShell. 148