IntelOwl: manage your Threat Intelligence at scale
-
Updated
Oct 1, 2026 - Python
IntelOwl: manage your Threat Intelligence at scale
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
Investigate malicious Windows logon by visualizing and analyzing Windows event log
Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
Your Everyday Threat Intelligence
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Browser forensics tool for Google Chrome, other Chromium-based browsers, and Mozilla Firefox
Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
Malcom - Malware Communications Analyzer
A DFIR tool written in Python.
Extract and aggregate threat intelligence.
A collection of resources for Threat Hunters
Historical Windows temporal memory-state research artifact for studying time-bound memory observations, validation limits, and defensive visibility.
A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs
Automation and Scaling of Digital Forensics Tools
Lookyloo is a web interface that allows users to capture a website page and then display a tree of domains that call each other.
A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.
To associate your repository with the dfir topic, visit your repo's landing page and select "manage topics."