Skip to content
#

dfir

Here are 2,280 public repositories matching this topic...

A 135+ tool DFIR toolkit, a live self-updating threat-intel platform, and a 332-tool MCP server — on one Cloudflare Workers deploy. MIT licensed. Portfolio: pranithjain.qzz.io

  • Updated Oct 7, 2026
  • TypeScript

Modern bilingual IT/EN honeypot and SOC analysis platform for attack monitoring, session correlation, threat intelligence, Suricata, MITRE ATT&CK, reporting and cybersecurity learning.

  • Updated Oct 7, 2026
  • Python

One command installs 670+ security tools on Debian/Ubuntu/Kali, Fedora, Arch, openSUSE and Termux. Its authorization-gated MCP server runs them in a disposable Kata Containers VM sandbox for Claude Code, Codex, Gemini CLI, OpenCode and other MCP clients. 872 agent skills for CTF, pentesting, bug bounty, DFIR and red/blue teams.

  • Updated Oct 7, 2026
  • Python

Threat-intel teardown + keyless live tracker of a multi-brand marketplace phishing-as-a-service (PhaaS) operation (Classiscam/Telekopye class) impersonating OLX, Subito, Kleinanzeigen & ~120 brands to steal card data + 3-D Secure/OTP. IOCs, kit analysis, detection signatures.

  • Updated Oct 7, 2026
  • HTML

Add this topic to your repo

To associate your repository with the dfir topic, visit your repo's landing page and select "manage topics."

Learn more