September 1, 2026

Links

404ensics // Field Resources

DFIR & Cyber Resource Directory

A curated collection of resources for digital forensics, incident response, SOC/NOC operations, malware analysis, threat hunting, OSINT, law enforcement, investigation, research and training.

⚠ Evidence Handling Notice

Exercise caution before uploading case evidence, confidential material, malware, customer data or privileged information to third-party services. Public analysis platforms may retain or share submitted files. Review each service’s privacy and submission policy and, where appropriate, use locally hosted forensic tools.

Ransomware & Extortion Tracking

Identify ransomware, monitor extortion activity and research current groups and campaigns.

FREE RANSOMWARE INTEL

Ransomware.live

Tracks ransomware groups, victims, leak sites and extortion activity. Particularly useful for determining whether an organization has appeared on a ransomware group’s victim site.

ransomware.live
FREE DECRYPTION IR

No More Ransom

International initiative providing ransomware information and free decryptors for supported ransomware families. An important early stop when investigating encrypted systems.

nomoreransom.org
FREE IDENTIFICATION UPLOAD

ID Ransomware

Helps identify ransomware families using ransom notes and encrypted file samples. Useful during initial incident identification and triage.

ID Ransomware
FREE DFIR CASE STUDIES

The DFIR Report

Detailed real-world intrusion case studies covering initial access, persistence, lateral movement, command and control and ransomware deployment.

thedfirreport.com

Threat Intelligence & IOC Investigation

Enrich IP addresses, domains, URLs, hashes and other indicators encountered during investigations.

IOC MALWARE UPLOAD

VirusTotal

Investigate files, hashes, URLs, domains and IP addresses using aggregated security-engine and threat-intelligence data.

virustotal.com
FREE THREAT INTEL IOC

abuse.ch

Community-focused threat intelligence project operating multiple services covering malware, botnets, malicious URLs and attacker infrastructure.

abuse.ch
FREE IOC API

ThreatFox

Search and share indicators of compromise associated with malware campaigns, including domains, URLs and IP addresses.

threatfox.abuse.ch
FREE URL MALWARE

URLhaus

Tracks URLs used for malware distribution. Useful for URL investigations, infrastructure research and security-feed enrichment.

urlhaus.abuse.ch
FREE MALWARE SAMPLES

MalwareBazaar

Malware sample exchange providing hashes, samples, metadata and APIs for legitimate research, reverse engineering and detection development.

bazaar.abuse.ch
IP REPUTATION API

AbuseIPDB

Community-driven reputation database for investigating IP addresses associated with scanning, brute force, spam and other abusive behavior.

abuseipdb.com
FREE OSINT THREAT INTEL

AlienVault OTX

Open threat-intelligence community where researchers publish IOC collections, campaign intelligence and threat pulses.

otx.alienvault.com
IP SCANNING SOC

GreyNoise

Helps determine whether observed IP traffic represents targeted activity or routine Internet scanning and background noise.

greynoise.io

Malware Analysis & Sandboxes

Analyze suspicious executables, documents, URLs and malware behavior.

SANDBOX MALWARE UPLOAD

ANY.RUN

Interactive malware sandbox for observing processes, network traffic, registry activity and malware behavior in near real time.

any.run
SANDBOX TRIAGE UPLOAD

Hatching Triage

Automated malware sandbox providing behavioral analysis, family identification, extracted indicators and investigation reports.

tria.ge
SANDBOX FILES UPLOAD

Hybrid Analysis

Online malware-analysis service for submitting suspicious files and examining associated behavioral and network indicators.

hybrid-analysis.com
SANDBOX MALWARE UPLOAD

Joe Sandbox

Automated malware-analysis environment supporting numerous file types and platforms with extensive behavior reporting.

joesandbox.com

Digital Forensics Tools

Core utilities for host, disk, memory, filesystem, Registry and artifact examination.

OPEN SOURCE MEMORY DFIR

Volatility Foundation

Home of the Volatility Framework, one of the standard open-source platforms for forensic examination of captured memory.

volatilityfoundation.org
OPEN SOURCE DISK FILESYSTEM

Autopsy

Graphical digital-forensics platform for disk-image analysis, deleted-file recovery, filesystem examination, timelines and forensic artifact processing.

autopsy.com
OPEN SOURCE FILESYSTEM CLI

The Sleuth Kit

Command-line forensic toolkit for investigating disk images and file systems. It also provides much of the underlying functionality used by Autopsy.

sleuthkit.org
OPEN SOURCE ENDPOINT IR

Velociraptor

Endpoint visibility, forensic collection and threat-hunting platform designed for remote and enterprise-scale incident response.

docs.velociraptor.app
FREE WINDOWS ARTIFACTS

Eric Zimmerman’s Tools

Highly regarded suite of Windows forensic tools covering Registry data, ShellBags, LNK files, Jump Lists, MFT records, timelines and other artifacts.

ericzimmerman.github.io
FREE TRIAGE COLLECTION

KAPE

Kroll Artifact Parser and Extractor rapidly collects and processes targeted forensic artifacts for triage and incident response.

KAPE
FREE METADATA FILES

ExifTool

Powerful metadata extraction utility supporting a huge range of image, document, audio, video and other file formats.

exiftool.org
OPEN SOURCE WINDOWS REGISTRY

RegRipper

Windows Registry forensic analysis framework using plugins to extract investigative artifacts from Registry hives.

RegRipper

Network Forensics, SOC & NOC

Packet analysis, network monitoring, intrusion detection and traffic investigation.

OPEN SOURCE PCAP NETWORK

Wireshark

Industry-standard packet capture and protocol-analysis platform for network troubleshooting, incident response and forensic investigations.

wireshark.org
OPEN SOURCE NSM HUNTING

Zeek

Network security monitoring framework that transforms network activity into rich structured logs for threat hunting and forensic investigation.

zeek.org
OPEN SOURCE IDS NETWORK

Suricata

High-performance IDS/IPS and network security monitoring engine supporting signatures, protocol inspection and traffic analysis.

suricata.io
FREE PCAP TRAINING

Malware-Traffic-Analysis.net

Excellent collection of malicious PCAPs, exercises and write-ups for network-forensics and SOC analyst training.

malware-traffic-analysis.net
FREE SOC INTEL

SANS Internet Storm Center

Internet threat monitoring, analysis and community diaries covering emerging attacks, malicious infrastructure and noteworthy activity.

isc.sans.edu

Detection Engineering & Threat Hunting

Map adversary behavior, create detections and understand legitimate tools abused by attackers.

FREE TTP HUNTING

MITRE ATT&CK

Knowledge base documenting adversary tactics and techniques observed in real-world intrusions. Fundamental for detection engineering and incident reporting.

attack.mitre.org
FREE DEFENSE MITRE

MITRE D3FEND

Defensive cybersecurity knowledge graph documenting countermeasures and defensive techniques that complement ATT&CK.

d3fend.mitre.org
OPEN SOURCE SIEM RULES

Sigma

Vendor-neutral detection-rule format for expressing suspicious behavior in logs and converting detections between different SIEM platforms.

sigmahq.io
OPEN SOURCE MALWARE RULES

YARA

Pattern-matching framework widely used to identify, classify and hunt malware and other files using textual and binary signatures.

YARA Documentation
FREE WINDOWS LOLBINS

LOLBAS

Catalog of legitimate Windows binaries, scripts and libraries that may be abused by attackers for execution, persistence and defense evasion.

lolbas-project.github.io
FREE LINUX UNIX

GTFOBins

Reference showing potentially unexpected or security-relevant capabilities of legitimate Unix binaries.

gtfobins.github.io

Internet Infrastructure & Exposure Research

Research domains, hosts, certificates, DNS infrastructure and Internet-facing systems.

HOSTS OSINT EXPOSURE

Shodan

Search engine for Internet-connected devices and services. Useful for infrastructure research and understanding Internet-facing exposure.

shodan.io
HOSTS CERTIFICATES OSINT

Censys

Internet host, service and certificate intelligence useful for pivoting between IP addresses, TLS certificates and infrastructure.

search.censys.io
DNS HISTORY OSINT

SecurityTrails

DNS and domain intelligence platform offering current and historical information useful when mapping infrastructure relationships.

securitytrails.com
FREE CERTIFICATES DOMAINS

crt.sh

Certificate Transparency search service useful for discovering certificates, domains and subdomains associated with infrastructure.

crt.sh
FREE DNS RECON

DNSDumpster

DNS research resource for identifying records, hosts and related infrastructure associated with a domain.

dnsdumpster.com
IP ASN NETWORK

IPinfo

IP intelligence providing ASN, organization, geolocation and network ownership information for IP-address investigations.

ipinfo.io

OSINT & Investigator Resources

Open-source intelligence resources for online investigations, verification and research.

FREE OSINT TOOLKIT

Bellingcat Investigation Toolkit

Curated collection covering geolocation, maps, satellite imagery, image verification, social media, archives and other OSINT disciplines.

Bellingcat Toolkit
FREE OSINT DIRECTORY

OSINT Framework

Categorized directory covering usernames, email addresses, domains, social networks, images, geolocation and many other OSINT resources.

osintframework.com
FREE ARCHIVE WEB

Wayback Machine

Historical web archive useful for investigating deleted, altered or previous versions of websites and online content.

web.archive.org
FREE IMAGE OSINT

TinEye

Reverse-image search useful for locating prior appearances, alternate versions and potential sources of investigative imagery.

tineye.com

Vulnerabilities & Exploitation Intelligence

Research vulnerabilities, exploitation likelihood and vulnerabilities actively used in attacks.

FREE CISA EXPLOITED

CISA Known Exploited Vulnerabilities

Authoritative catalog of vulnerabilities known to have been exploited in the wild. Valuable for incident investigation and remediation prioritization.

CISA KEV Catalog
FREE CVE NIST

NIST National Vulnerability Database

Vulnerability database containing CVE details, scoring, affected configurations and technical references.

nvd.nist.gov
FREE CVE REFERENCE

CVE Program

Official program providing standardized identifiers for publicly disclosed cybersecurity vulnerabilities.

cve.org
FREE EPSS RISK

FIRST EPSS

Exploit Prediction Scoring System estimates the probability that a vulnerability will be exploited in the wild.

first.org/epss

DFIR Training & Reference Evidence

Practice investigations using forensic datasets, challenge environments and documented test evidence.

FREE DATASETS TRAINING

Digital Corpora

Forensic datasets including disk images, memory captures and other material intended for education, testing and research.

digitalcorpora.org
FREE NIST EVIDENCE

NIST CFReDS

Computer Forensic Reference Data Sets provide documented simulated digital evidence for forensic tool testing and investigator training.

cfreds.nist.gov
TRAINING BLUE TEAM LABS

CyberDefenders

Practical blue-team labs covering digital forensics, SOC operations, endpoint investigation, malware analysis and threat hunting.

cyberdefenders.org
TRAINING DFIR SOC

Blue Team Labs Online

Defensive-security challenge environment covering SOC investigations, DFIR, threat intelligence and incident response.

blueteamlabs.online

Everyday Analyst Utilities

Useful tools that regularly earn a place in an investigator’s browser bookmarks.

FREE DECODING ANALYSIS

CyberChef

GCHQ’s browser-based data analysis toolkit for encoding, decoding, hashing, extraction, compression and hundreds of other transformations.

CyberChef
BREACH EMAIL OSINT

Have I Been Pwned

Determine whether email addresses or domains have appeared in known public breach datasets.

haveibeenpwned.com
FILES REFERENCE

FileInfo

Reference database for file extensions, formats and associated applications. Useful when unusual files appear during examinations.

fileinfo.com
FREE NETWORK REFERENCE

IANA Protocol Registries

Authoritative Internet protocol registries covering ports, protocol parameters and other standards information.

iana.org/protocols

Incident Response, Standards & Law Enforcement

Government, standards and cybercrime resources relevant to defenders and investigators.

FREE GOV IR

CISA

Cybersecurity and Infrastructure Security Agency resources covering incident response, advisories, vulnerabilities and defensive guidance.

cisa.gov
FREE LAW ENFORCEMENT REPORTING

FBI Internet Crime Complaint Center

IC3 provides a reporting mechanism for Internet-enabled crime and fraud and publishes cybercrime information relevant to investigators and victims.

ic3.gov
FREE LAW ENFORCEMENT EU

Europol EC3

European Cybercrime Centre supporting law-enforcement operations and coordination against serious and organized cybercrime.

Europol EC3
FREE NIST STANDARDS

NIST Cybersecurity

Cybersecurity standards, publications, frameworks and technical guidance published by the National Institute of Standards and Technology.

nist.gov/cybersecurity
INCIDENT RESPONSE CSIRT STANDARDS

FIRST

Global Forum of Incident Response and Security Teams providing standards, resources and collaboration for security and incident-response teams.

first.org