Analyzing tcpdump network logs to diagnose DNS failures and translating packet data into an incident report.
-
Updated
Sep 25, 2026
Analyzing tcpdump network logs to diagnose DNS failures and translating packet data into an incident report.
Digital forensics case study demonstrating evidence acquisition, integrity verification, deleted-data recovery, and artifact analysis.
Collects live Windows artifacts, evaluates them against built-in detection rules, and tells you whether the host is compromised. One script, no dependencies.
ForensicTools automatise l’acquisition forensique multi-plateforme (Windows, Linux, macOS) : collecte d’artefacts volatils et persistants, capture mémoire, copie bit-à-bit des disques, chaîne de custody, gestion des dossiers d’enquête et orchestration d’outils d’analyse (Volatility3, Plaso, YARA, Sleuth Kit).
Programmable digital forensics framework for endpoint investigation, evidence integrity, and verification.
Enterprise-grade SOC Triage & DevSecOps Platform. Features multi-source log ingestion (Syslog, CloudTrail, GitHub Actions), stateful attack campaign correlation, threat intel consensus caching, automated SOAR playbooks, and an interactive MITRE ATT&CK® heatmap dashboard with OpenAPI/Swagger support
To associate your repository with the incident-response-forensics topic, visit your repo's landing page and select "manage topics."