<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>dfir</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/541/feed"/>
    <updated>2026-08-01T19:05:29+00:00</updated>
    <id>https://links.biapy.com/guest/tags/541/feed</id>
            <entry>
            <id>https://links.biapy.com/links/12803</id>
            <title type="text"><![CDATA[EventHawk]]></title>
            <link rel="alternate" href="https://github.com/Mihir-Choudhary/EventHawk" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12803"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Windows EVTX log analysis for DFIR — fast parsing, ATT&amp;amp;CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mode (Arrow/DuckDB) for 10M+ events.]]>
            </summary>
            <updated>2026-05-21T11:58:01+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12802</id>
            <title type="text"><![CDATA[VanGuard]]></title>
            <link rel="alternate" href="https://github.com/ridgelinecyberdefence/vanguard" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12802"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Enterprise Incident Response Toolkit.

 Cross-platform incident response toolkit. 28 pre-built use cases, single binary, zero install. Memory, disk, network, and cloud collection with automated timeline generation. 

Cross-platform DFIR toolkit for enterprise incident response. Velociraptor-native, air-gap compatible, portable — no installation required.

VanGuard is a self-contained incident response toolkit built in Go that gives DFIR teams a single binary for triage, threat hunting, memory forensics, disk collection, remote operations, and Velociraptor management — on both Windows and Linux, with or without network access.]]>
            </summary>
            <updated>2026-05-21T11:57:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12335</id>
            <title type="text"><![CDATA[Anthropic Cybersecurity Skills]]></title>
            <link rel="alternate" href="https://www.mahipal.engineer/Anthropic-Cybersecurity-Skills/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12335"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[734 Cybersecurity Skills for AI Agents.
734+ AI-Ready Skills for Claude Code &amp;amp; More.

The largest open-source library of structured cybersecurity skills following the agentskills.io standard. Deploy instantly to Claude Code, GitHub Copilot, Cursor, and 26+ platforms. 

- [Anthropic Cybersecurity Skills @ GitHub](https://github.com/mukul975/Anthropic-Cybersecurity-Skills).]]>
            </summary>
            <updated>2026-03-28T11:55:45+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/366</id>
            <title type="text"><![CDATA[Kanvas]]></title>
            <link rel="alternate" href="https://findevil.io/Kanvas-page/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/366"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Kanvas for Incident Response.

A DF/IR case management tool that provides a unified workspace for investigators enabling key workflows to be completed without switching between multiple applications.

- [Kanvas @ GitHub](https://github.com/WithSecureLabs/Kanvas).]]>
            </summary>
            <updated>2026-01-20T15:30:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1165</id>
            <title type="text"><![CDATA[MemProcFS-Analyzer]]></title>
            <link rel="alternate" href="https://github.com/LETHAL-FORENSICS/MemProcFS-Analyzer" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1165"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Automated Forensic Analysis of Windows Memory Dumps for DFIR.

MemProcFS-Analyzer.ps1 is a PowerShell script utilized to simplify the usage of MemProcFS and to optimize your memory analysis workflow.]]>
            </summary>
            <updated>2025-08-28T19:10:56+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4735</id>
            <title type="text"><![CDATA[Forensic Miner]]></title>
            <link rel="alternate" href="https://github.com/YosfanEilay/ForensicMiner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4735"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

ForensicMiner, a PowerShell-based DFIR automation tool, revolutionizes the field of digital investigations. Designed for efficiency, it automates artifact and evidence collection from Windows machines. Compatibility with Flacon Crowdstrike RTR and Palo Alto Cortex XDR Live Terminal, along with its swift performance and user-friendly interface, makes ForensicMiner an indispensable asset for investigators navigating the complexities of forensic analysis. Streamlined and effective, this tool sets a new standard in the realm of digital forensics.]]>
            </summary>
            <updated>2025-08-29T05:06:58+00:00</updated>
        </entry>
    </feed>
