DFIR & Cyber Resource Directory
A curated collection of resources for digital forensics, incident response, SOC/NOC operations, malware analysis, threat hunting, OSINT, law enforcement, investigation, research and training.
Exercise caution before uploading case evidence, confidential material, malware, customer data or privileged information to third-party services. Public analysis platforms may retain or share submitted files. Review each service’s privacy and submission policy and, where appropriate, use locally hosted forensic tools.
Ransomware & Extortion Tracking
Identify ransomware, monitor extortion activity and research current groups and campaigns.
Ransomware.live
Tracks ransomware groups, victims, leak sites and extortion activity. Particularly useful for determining whether an organization has appeared on a ransomware group’s victim site.
ransomware.liveNo More Ransom
International initiative providing ransomware information and free decryptors for supported ransomware families. An important early stop when investigating encrypted systems.
nomoreransom.orgID Ransomware
Helps identify ransomware families using ransom notes and encrypted file samples. Useful during initial incident identification and triage.
ID RansomwareThe DFIR Report
Detailed real-world intrusion case studies covering initial access, persistence, lateral movement, command and control and ransomware deployment.
thedfirreport.comThreat Intelligence & IOC Investigation
Enrich IP addresses, domains, URLs, hashes and other indicators encountered during investigations.
VirusTotal
Investigate files, hashes, URLs, domains and IP addresses using aggregated security-engine and threat-intelligence data.
virustotal.comabuse.ch
Community-focused threat intelligence project operating multiple services covering malware, botnets, malicious URLs and attacker infrastructure.
abuse.chThreatFox
Search and share indicators of compromise associated with malware campaigns, including domains, URLs and IP addresses.
threatfox.abuse.chURLhaus
Tracks URLs used for malware distribution. Useful for URL investigations, infrastructure research and security-feed enrichment.
urlhaus.abuse.chMalwareBazaar
Malware sample exchange providing hashes, samples, metadata and APIs for legitimate research, reverse engineering and detection development.
bazaar.abuse.chAbuseIPDB
Community-driven reputation database for investigating IP addresses associated with scanning, brute force, spam and other abusive behavior.
abuseipdb.comAlienVault OTX
Open threat-intelligence community where researchers publish IOC collections, campaign intelligence and threat pulses.
otx.alienvault.comGreyNoise
Helps determine whether observed IP traffic represents targeted activity or routine Internet scanning and background noise.
greynoise.ioMalware Analysis & Sandboxes
Analyze suspicious executables, documents, URLs and malware behavior.
ANY.RUN
Interactive malware sandbox for observing processes, network traffic, registry activity and malware behavior in near real time.
any.runHatching Triage
Automated malware sandbox providing behavioral analysis, family identification, extracted indicators and investigation reports.
tria.geHybrid Analysis
Online malware-analysis service for submitting suspicious files and examining associated behavioral and network indicators.
hybrid-analysis.comJoe Sandbox
Automated malware-analysis environment supporting numerous file types and platforms with extensive behavior reporting.
joesandbox.comDigital Forensics Tools
Core utilities for host, disk, memory, filesystem, Registry and artifact examination.
Volatility Foundation
Home of the Volatility Framework, one of the standard open-source platforms for forensic examination of captured memory.
volatilityfoundation.orgAutopsy
Graphical digital-forensics platform for disk-image analysis, deleted-file recovery, filesystem examination, timelines and forensic artifact processing.
autopsy.comThe Sleuth Kit
Command-line forensic toolkit for investigating disk images and file systems. It also provides much of the underlying functionality used by Autopsy.
sleuthkit.orgVelociraptor
Endpoint visibility, forensic collection and threat-hunting platform designed for remote and enterprise-scale incident response.
docs.velociraptor.appEric Zimmerman’s Tools
Highly regarded suite of Windows forensic tools covering Registry data, ShellBags, LNK files, Jump Lists, MFT records, timelines and other artifacts.
ericzimmerman.github.ioKAPE
Kroll Artifact Parser and Extractor rapidly collects and processes targeted forensic artifacts for triage and incident response.
KAPEExifTool
Powerful metadata extraction utility supporting a huge range of image, document, audio, video and other file formats.
exiftool.orgRegRipper
Windows Registry forensic analysis framework using plugins to extract investigative artifacts from Registry hives.
RegRipperNetwork Forensics, SOC & NOC
Packet analysis, network monitoring, intrusion detection and traffic investigation.
Wireshark
Industry-standard packet capture and protocol-analysis platform for network troubleshooting, incident response and forensic investigations.
wireshark.orgZeek
Network security monitoring framework that transforms network activity into rich structured logs for threat hunting and forensic investigation.
zeek.orgSuricata
High-performance IDS/IPS and network security monitoring engine supporting signatures, protocol inspection and traffic analysis.
suricata.ioMalware-Traffic-Analysis.net
Excellent collection of malicious PCAPs, exercises and write-ups for network-forensics and SOC analyst training.
malware-traffic-analysis.netSANS Internet Storm Center
Internet threat monitoring, analysis and community diaries covering emerging attacks, malicious infrastructure and noteworthy activity.
isc.sans.eduDetection Engineering & Threat Hunting
Map adversary behavior, create detections and understand legitimate tools abused by attackers.
MITRE ATT&CK
Knowledge base documenting adversary tactics and techniques observed in real-world intrusions. Fundamental for detection engineering and incident reporting.
attack.mitre.orgMITRE D3FEND
Defensive cybersecurity knowledge graph documenting countermeasures and defensive techniques that complement ATT&CK.
d3fend.mitre.orgSigma
Vendor-neutral detection-rule format for expressing suspicious behavior in logs and converting detections between different SIEM platforms.
sigmahq.ioYARA
Pattern-matching framework widely used to identify, classify and hunt malware and other files using textual and binary signatures.
YARA DocumentationLOLBAS
Catalog of legitimate Windows binaries, scripts and libraries that may be abused by attackers for execution, persistence and defense evasion.
lolbas-project.github.ioGTFOBins
Reference showing potentially unexpected or security-relevant capabilities of legitimate Unix binaries.
gtfobins.github.ioInternet Infrastructure & Exposure Research
Research domains, hosts, certificates, DNS infrastructure and Internet-facing systems.
Shodan
Search engine for Internet-connected devices and services. Useful for infrastructure research and understanding Internet-facing exposure.
shodan.ioCensys
Internet host, service and certificate intelligence useful for pivoting between IP addresses, TLS certificates and infrastructure.
search.censys.ioSecurityTrails
DNS and domain intelligence platform offering current and historical information useful when mapping infrastructure relationships.
securitytrails.comcrt.sh
Certificate Transparency search service useful for discovering certificates, domains and subdomains associated with infrastructure.
crt.shDNSDumpster
DNS research resource for identifying records, hosts and related infrastructure associated with a domain.
dnsdumpster.comIPinfo
IP intelligence providing ASN, organization, geolocation and network ownership information for IP-address investigations.
ipinfo.ioOSINT & Investigator Resources
Open-source intelligence resources for online investigations, verification and research.
Bellingcat Investigation Toolkit
Curated collection covering geolocation, maps, satellite imagery, image verification, social media, archives and other OSINT disciplines.
Bellingcat ToolkitOSINT Framework
Categorized directory covering usernames, email addresses, domains, social networks, images, geolocation and many other OSINT resources.
osintframework.comWayback Machine
Historical web archive useful for investigating deleted, altered or previous versions of websites and online content.
web.archive.orgTinEye
Reverse-image search useful for locating prior appearances, alternate versions and potential sources of investigative imagery.
tineye.comVulnerabilities & Exploitation Intelligence
Research vulnerabilities, exploitation likelihood and vulnerabilities actively used in attacks.
CISA Known Exploited Vulnerabilities
Authoritative catalog of vulnerabilities known to have been exploited in the wild. Valuable for incident investigation and remediation prioritization.
CISA KEV CatalogNIST National Vulnerability Database
Vulnerability database containing CVE details, scoring, affected configurations and technical references.
nvd.nist.govCVE Program
Official program providing standardized identifiers for publicly disclosed cybersecurity vulnerabilities.
cve.orgFIRST EPSS
Exploit Prediction Scoring System estimates the probability that a vulnerability will be exploited in the wild.
first.org/epssDFIR Training & Reference Evidence
Practice investigations using forensic datasets, challenge environments and documented test evidence.
Digital Corpora
Forensic datasets including disk images, memory captures and other material intended for education, testing and research.
digitalcorpora.orgNIST CFReDS
Computer Forensic Reference Data Sets provide documented simulated digital evidence for forensic tool testing and investigator training.
cfreds.nist.govCyberDefenders
Practical blue-team labs covering digital forensics, SOC operations, endpoint investigation, malware analysis and threat hunting.
cyberdefenders.orgBlue Team Labs Online
Defensive-security challenge environment covering SOC investigations, DFIR, threat intelligence and incident response.
blueteamlabs.onlineEveryday Analyst Utilities
Useful tools that regularly earn a place in an investigator’s browser bookmarks.
CyberChef
GCHQ’s browser-based data analysis toolkit for encoding, decoding, hashing, extraction, compression and hundreds of other transformations.
CyberChefHave I Been Pwned
Determine whether email addresses or domains have appeared in known public breach datasets.
haveibeenpwned.comFileInfo
Reference database for file extensions, formats and associated applications. Useful when unusual files appear during examinations.
fileinfo.comIANA Protocol Registries
Authoritative Internet protocol registries covering ports, protocol parameters and other standards information.
iana.org/protocolsIncident Response, Standards & Law Enforcement
Government, standards and cybercrime resources relevant to defenders and investigators.
CISA
Cybersecurity and Infrastructure Security Agency resources covering incident response, advisories, vulnerabilities and defensive guidance.
cisa.govFBI Internet Crime Complaint Center
IC3 provides a reporting mechanism for Internet-enabled crime and fraud and publishes cybercrime information relevant to investigators and victims.
ic3.govEuropol EC3
European Cybercrime Centre supporting law-enforcement operations and coordination against serious and organized cybercrime.
Europol EC3NIST Cybersecurity
Cybersecurity standards, publications, frameworks and technical guidance published by the National Institute of Standards and Technology.
nist.gov/cybersecurityFIRST
Global Forum of Incident Response and Security Teams providing standards, resources and collaboration for security and incident-response teams.
first.org