Field reference for BTL1 and Tier 1 SOC work — grep-ready cheatsheets, SPL queries, Volatility workflows, live response commands
Scans a disk image, file, or directory and extracts features such as email addresses, URLs, credit card numbers, phone numbers, and other fo…
EDR & AV Bypass Arsenal— a comprehensive collection of tools, patches, and techniques for evading modern EDR and antivirus defenses.
takes shellcode bad-bytes and banishes them, returning cleaned shellcode with preserved functionalities
The FLARE team's open-source tool to identify capabilities in executable files.
Malware Configuration And Payload Extraction
Cyber-investigation Analysis Standard Expression (CASE) Ontology
Official code for CAT-Net: Compression Artifact Tracing Network. Image manipulation detection and localization.
⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident re…
CDIR (Cyber Defense Institute Incident Response) Collector - live collection tool based on oss tool/library
Rapidly Search and Hunt through Windows Forensic Artefacts
This repo contains IOC, malware and malware analysis associated with Public cloud
Local-first AWS forensic engine. Finds waste via dependency graph analysis and enables safe remediation with Terraform state restoration.
Coeus 🌐 is an OSINT ToolBox empowering users with tools for effective intelligence gathering from open sources. From social media monitoring…
Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
Common CTF Challenges is a collection of tools and resources to help individuals improve their Capture the Flag (CTF) skills. Cover a wide r…
Configuration Extractors for Malware
Cortex: a Powerful Observable Analysis and Active Response Engine
The following repository is used by TheHive Project to develop and store Cortex analyzers & responders.
CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taking,…
Course Repository for University of Cincinnati Malware Analysis Class (CS[567]038)
List of tools and commands that may be helpful in CTFs
面向小白用户的 CTF / 逆向 Skills 整合包:自动分流、头脑风暴、教学模式、比赛模式、只提示模式