All you need to remember is triage.zip 🚀
It's a prebuilt Velociraptor collector configured to grab all the things you probably need for initial forensic analysis.
All you need to remember is triage.zip 🚀
It's a prebuilt Velociraptor collector configured to grab all the things you probably need for initial forensic analysis.
Provided artifacts:
- Disk Triage Collection
- Memory Image + pagefile.sys:
- PCAP File
Link: bluecapesecurity.com/courses/elev...
Provided artifacts:
- Disk Triage Collection
- Memory Image + pagefile.sys:
- PCAP File
Link: bluecapesecurity.com/courses/elev...
Designed for SOC/IR teams, NIMS helps streamline incident management and collaboration using Notion's powerful database features.
#InfoSec #DFIR #IncidentResponse #SecOps #Notion
Designed for SOC/IR teams, NIMS helps streamline incident management and collaboration using Notion's powerful database features.
#InfoSec #DFIR #IncidentResponse #SecOps #Notion
* github.com/tomchop/open...: Scan memory images using @volatilityfoundation.org plugins. Supports Yara rules
* github.com/tomchop/open... - Run Yara rules on a directory. Supports third-party systems like #Yeti!
It can easily be integrated with other hunting & DFIR tools such as Velociraptor & OpenRelik.
Check it out 🔥🔥:
github.com/Yamato-Secur...
#threathunting #DFIR #sigma #cybersecurity #infosec
It can easily be integrated with other hunting & DFIR tools such as Velociraptor & OpenRelik.
Check it out 🔥🔥:
github.com/Yamato-Secur...
#threathunting #DFIR #sigma #cybersecurity #infosec