meta data for this page
  •  

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
soc:tools:start [2026/06/10 13:08] titannetsoc:tools:start [2026/06/10 15:04] (current) titannet
Line 6: Line 6:
   * [[kibana]]   * [[kibana]]
   * [[splunk]]   * [[splunk]]
- 
  
  
 ===== Network ===== ===== Network =====
  
-[[wireshark]]+  * [[wireshark]]
  
  
Line 17: Line 16:
 ===== IR ===== ===== IR =====
  
-  * [[X-ways]] +  * [[velociraptor]] 
-  * [[Axiom]] +    * remote artefact collection and administration 
-  * [[F-Response]] +  * [[iris]] 
-  * [[Arsenal Image Mounter]] +    * Collaborative Incident Response Platform 
-  * [[Magnet RAM Capture]] +  * [[x_ways]] 
-  * [[Exiftool]] +  * [[axiom]] 
-  * [[SQLite Database Browser]] +  * [[f_Response]] 
-  * [[OST/PST Viewer]] +  * [[arsenal_image_mounter]] 
-  * [[Registry Viewer]] +  * [[magnet_ram_capture]] 
-  * [[Regripper]] +  * [[exiftool]] 
-  * [[Ghidra]]+  * [[sqlite_database_browser]] 
 +  * [[ost_pst_viewer]] 
 +  * [[registry_viewer]] 
 +  * [[regripper]] 
 +  * [[ghidra]] 
 + 
 +===== Commandline ===== 
 + 
 + 
 +  * [[evtwalk]] 
 +    * Parse Windows Event Logs 
 + 
 + 
 +  * [[dissect]] 
 +    * Analysis of file systems and images 
 +  * [[timelines] 
 +    * tools like [[plaso]], [[log2timeline]], [[timesketch]] 
 +  * [[hayabusa]] 
 +    * Parses windows event logs or sysmon/linux 
 + 
 + 
 +===== Windows GUI ===== 
 + 
 +  * [[memprocfs]] 
 + 
 +  * [[wireshark]] 
 +  * [[networkminer]] 
 +  * [[snort]] 
 +  * [[zeek]] 
 +  * [[yaru]] 
 +    * TZworks, yet another registry utility 
 +  * [[usp]] 
 +    * TZWorks, USB parser 
 +  * [[sysinternals]] 
 +    * tcpview, resmon,  
 + 
 + 
 +===== Malware Analysis ===== 
 + 
 +  * [[https://threatfox.abuse.ch]] 
 +  * [[https://bazaar.abuse.ch]] 
 +  * [[https://thalosintelligence.com]] 
 +  * [[https://www.virustotal.com]] 
 + 
 + 
 +==== Data Collection ==== 
 + 
 +  * [[CyLR]] 
 +    * Collect artefacts on Win, Linux and MacOS 
 +  * [[UAC]] 
 +    * Unix Artefacts Collector 
 +  * [[ntfswalk]] 
 +    * ntfswalk, gena (gui) 
 +  * Scripts 
 + 
 + 
 +==== Active Directory ==== 
 + 
 + * [[ping_castle]]
  
  
Line 36: Line 93:
 ==== Forensics ==== ==== Forensics ====
  
 +
 +    *