TotalRecall

Digital threat analyzer

An open source tool for analyzing digital artifacts to detect potential security threats

Based on the Volatility framework, this script will run various plugins as well as create a timeline, or use YARA/ClamAV/VirusTotal to find badness.

GitHub

49 stars
14 watching
9 forks
Language: Python
last commit: over 9 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
tripwire/tardisAn intelligence platform for threat analysis and incident response123
stratosphereips/manatiAn open-source tool utilizing machine learning to assist threat analysts in identifying security problems.112
mlsecproject/tiq-testAnalyzes threat intelligence feeds using statistical methods and data visualization.173
crits/critsAn analytic tool for cyber threat analysis and malware correlation, providing a platform for researchers to conduct analyses and save results.894
debasishm89/burpyA tool that analyzes web application security by parsing Burp Suite logs and generating reports.120
yevh/taac-aiAn AI-driven tool for analyzing service descriptions and identifying security threats.118
thehive-project/cortex-analyzersDevelops and stores Cortex analyzers & responders for incident response and threat intelligence.437
mlsecproject/combineTool to gather Threat Intelligence indicators from publicly available sources657
svdwi/blueboxAnalyzes and enriches threat intelligence data from various sources to help detect malicious files, URLs, and domains.39
sk4la/plastA modular threat-hunting tool framework for detecting indicators of compromise in incident-response operations.17
dissectmalware/officeforensictoolsA Python-based collection of tools for gathering forensic information from Office documents26
binarydefense/goatriderTool to compare IP addresses or hostnames to threat intelligence feeds and detect potential security threats.138
michael-yip/threattrackerMonitors and alerts on IOCs from Google Custom Search Engines and Safe Browsing APIs.66
ptr32void/ostricaA framework to collect and visualize threat intelligence information from various sources in a flexible and plugin-based architecture.309
idiom/pftriageTool to analyze files during malware analysis and triage by extracting properties and detecting malicious indicators.77