diffy

Host analyzer

An incident response tool that helps digital forensics teams analyze and prioritize suspicious hosts in cloud environments

no_entry (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR) teams quickly identify suspicious hosts on which to focus their response.

GitHub

635 stars
144 watching
59 forks
Language: Python
last commit: over 2 years ago
Linked from 2 awesome lists

dfirforensicssecurity

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
fox-it/dissectA digital forensics framework that provides tools and parsers to analyze forensic artefacts from various disk and file formats.939
hackvertor/diffyA Java application that displays differences between two responses using color-coded formatting.0
diogo-fernan/ir-rescueA tool for comprehensively collecting host forensic data during incident response and analysis.466
dhoelzer/showmethepacketsTools and resources for network monitoring and analysis used in the SANS SEC503 course214
codeyourweb/fastfinderTools for detecting suspicious files and directories on Windows and Linux endpoints.234
idiom/pftriageTool to analyze files during malware analysis and triage by extracting properties and detecting malicious indicators.77
dynetics/malfunctionTools for analyzing and comparing malware at a function level using fuzzy hashing algorithms192
ydkhatri/mac_aptA digital forensics tool for analyzing macOS and iOS systems790
dissectmalware/officeforensictoolsA Python-based collection of tools for gathering forensic information from Office documents26
detuxsandbox/detuxAnalyzes and captures malware traffic on Linux sandboxed environments using QEMU hypervisor and various CPU architectures.261
dfirkuiper/kuiperAn investigation platform for parsing and analyzing digital evidence, streamlining workflows and improving collaboration.777
uqcyber/coldpressAutomates malware analysis workflow by extracting features and indicators of compromise from malicious files using various tools and libraries.16
fox-it/dissect.targetProvides a programming API and command line tools to access various data sources inside disk images or file collections.48
fox-it/dissect.xfsA Dissect module implementing a parser for the XFS file system, commonly used by RedHat Linux distributions.2
securityjoes/forensicminerAutomates evidence collection and analysis from Windows machines using PowerShell.149