For the complete documentation index, see llms.txt. This page is also available as Markdown.

Blue - DFIR: Digital Forensics and Incident Response

DFIR resources for incident response, forensic triage, Windows and Linux commands, memory forensics, malware analysis, and evidence collection.

DFIR focuses on evidence, timelines, containment, eradication, and recovery after suspicious activity or a confirmed compromise. This section is for hands-on incident response and forensic analysis: remote triage, host commands, event logs, evidence collection, memory forensics, sandboxing, file analysis, malware analysis, and reverse engineering.

For detection engineering, SIEM rules, and Sysmon configuration, use Event Detection. For reputation and enrichment lookups, use Threat Data.

Event DetectionThreat Data

DFIR Resource Collections

Training, CTFs, labs, and course links have moved to Training.

Training and Resources

Incident Response Process

Report Writing and Documentation

Host Collection and IR Frameworks

Malware and IR Scanners

YARA, Loki, THOR Lite, Fenrir, and Binalyze IREC are maintained on the YARA page.

YARA

Memory scanners such as pe-sieve are maintained with memory forensics.

Memory Forensics

DFIR Commands

Interact with remote machineWindows System EnumerationWindows Process InformationWindows DFIR ChecksWindows DFIR Check by MITRE TacticWindows Event LogsIR Event Log CheatsheetWindows Remediation CommandsLinux DFIR CommandsMacOS DFIR Commands

Forensic Workstations and Frameworks

File Systems, Imaging, and Recovery

Detailed file analysis and carving guidance lives on File/Binary Analysis.

File/Binary Analysis

Useful extraction and recovery tools:

Forensic imaging:

Platform-Specific Forensics

Windows, Linux, and macOS command references are linked above. macOS artifact resources:

Malware Analysis and Reverse Engineering

Malware analysis resources are split by workflow:

MalwareSandboxingReverse Engineering

Analyze malware in an isolated VM or lab network. Do not detonate samples on production systems.

Legacy / Deprecated Tools

These are kept for historical reference or specific legacy cases.

  • Redline by FireEye/Mandiant - Legacy host investigation tool. Original FireEye links may no longer be maintained.

  • CrowdResponse - Static host data collection tool.

  • Gmer Rootkit Scanner - Rootkit detection/removal utility.

  • chkrootkit - Local Unix rootkit checks.

  • RKHunter - Unix rootkit scanner.

  • Galleta - Internet Explorer cookie file analysis.

  • Pasco - Internet Explorer cache file analysis.

  • herdProtect - Legacy second-opinion cloud malware scanner; verify availability before use.

Last updated