IRCoreForensicFramework

Incident responder tool

Automates incident response actions to gather and process forensic artefacts from remote systems

Powershell / C# based cross platform forensic framework based for live incident response

GitHub

22 stars
5 watching
5 forks
Language: PowerShell
last commit: over 4 years ago

Related projects:

Repository Description Stars
davehull/kansa A modular incident response framework in Powershell 1,565
ajmartel/irtriage Automated incident response tool for collecting critical system information during forensic analysis of Windows systems. 130
atc-project/atc-react A knowledge base of actionable Incident Response techniques 615
certsocietegenerale/irm Operational guidelines and best practices for handling various types of security incidents 982
invoke-ir/powerforensics A C#-based framework for analyzing and investigating hard drive forensic data 1,389
cyberdefenseinstitute/cdir A tool designed to collect data from Windows systems during an incident response 154
demisto/cops Standardized framework for creating and sharing incident response processes in a shared language 151
tap-ir/tapir An incident response framework with multi-user support, providing plugins for file analysis and a REST API for data access 45
certsocietegenerale/fir A cybersecurity incident management platform for tracking and managing security incidents in real-time. 1,751
cisagov/untitledgoosetool A tool for investigating and responding to security incidents in cloud-based Microsoft environments. 917
dfir-iris/iris-web A collaborative platform for incident responders to share technical details during investigations 1,091
pjrinaldi/wombatforensics A multi-threaded GUI forensic analysis tool for Linux 48
cyb3rfox/aurora-incident-response Tool designed to help incident responders track findings and tasks during investigations 772
opensourcesec/cirtkit A comprehensive toolset for digital forensics and incident response analysis using Python 142
securityjoes/forensicminer Automates evidence collection and analysis from Windows machines using PowerShell. 149