add knowledgebase

This commit is contained in:
overcuriousity
2025-07-15 22:47:56 +02:00
parent d18cc060e5
commit a057120d7a
10 changed files with 514 additions and 222 deletions

View File

@@ -2,9 +2,11 @@ tools:
# Disk & File System Analysis Tools
- name: Autopsy
description: >-
Open-Source digitale Forensik-Plattform mit grafischer Benutzeroberfläche
Open-Source digitale Forensik-Anwendung mit grafischer Benutzeroberfläche
für Festplatten- und Dateisystemanalyse. Besonders geeignet für die
Analyse-Phase mit umfangreichen Carving- und Timeline-Funktionen.
Auswertungs- und Analyse-Phase mit umfangreichen Carving- und Timeline-Funktionen.
DIE Alternative für kommerzielle Software im Bereich, wenn es um die
kriminalistische Untersuchung von Images geht.
domains:
- incident-response
- law-enforcement
@@ -13,15 +15,16 @@ tools:
- data-collection
- examination
- analysis
- reporting
platforms:
- Windows
- Linux
- macOS
- Linux (Snap-Paket)
skillLevel: intermediate
accessType: download
url: https://www.autopsy.com/
projectUrl: ''
license: Apache 2.0
knowledgebase:
tags:
- disk-imaging
- file-carving
@@ -56,6 +59,7 @@ tools:
url: https://www.volatilityfoundation.org/
projectUrl: ''
license: VSL
knowledgebase:
tags:
- memory-analysis
- malware-detection
@@ -74,6 +78,7 @@ tools:
Kollaborative Security-Incident-Response-Plattform für SOCs, CERTs und
Sicherheitsteams mit Case-Management. Ideal für alle Phasen einer
Untersuchung, besonders für Koordination und Berichterstattung.
Keine Erfahrungswerte.
domains:
- incident-response
- law-enforcement
@@ -83,7 +88,6 @@ tools:
- examination
- analysis
- reporting
- collaboration
platforms:
- Web
skillLevel: intermediate
@@ -91,6 +95,7 @@ tools:
url: https://strangebee.com/
projectUrl: ''
license: Community Edition (Free) / Commercial
knowledgebase:
tags:
- case-management
- team-collaboration
@@ -117,7 +122,6 @@ tools:
- data-collection
- examination
- analysis
- collaboration
platforms:
- Web
skillLevel: intermediate
@@ -125,6 +129,7 @@ tools:
url: https://misp-project.org/
projectUrl: https://misp.cc24.dev
license: AGPL-3.0
knowledgebase:
tags:
- threat-intelligence
- ioc-sharing
@@ -156,6 +161,7 @@ tools:
url: https://timesketch.org/
projectUrl: https://timesketch.cc24.dev
license: Apache 2.0
knowledgebase:
tags:
- timeline-analysis
- data-visualization
@@ -190,6 +196,7 @@ tools:
url: https://www.wireshark.org/
projectUrl: ''
license: GPL-2.0
knowledgebase:
tags:
- packet-capture
- protocol-analysis
@@ -224,6 +231,7 @@ tools:
url: https://www.magnetforensics.com/products/magnet-axiom/
projectUrl: ''
license: Proprietary
knowledgebase:
tags:
- mobile-forensics
- cloud-acquisition
@@ -255,6 +263,7 @@ tools:
url: https://cellebrite.com/en/ufed/
projectUrl: ''
license: Proprietary
knowledgebase:
tags:
- mobile-extraction
- physical-extraction
@@ -283,6 +292,7 @@ tools:
url: https://github.com/cert-ee/cuckoo3
projectUrl: ''
license: GPL-3.0
knowledgebase:
tags:
- dynamic-analysis
- behavior-monitoring
@@ -314,6 +324,7 @@ tools:
url: https://ghidra-sre.org/
projectUrl: ''
license: Apache 2.0
knowledgebase:
tags:
- reverse-engineering
- disassembly
@@ -346,6 +357,7 @@ tools:
url: https://plaso.readthedocs.io/
projectUrl: ''
license: Apache 2.0
knowledgebase:
tags:
- timeline-generation
- log-parsing
@@ -376,6 +388,7 @@ tools:
url: https://gchq.github.io/CyberChef/
projectUrl: ''
license: Apache 2.0
knowledgebase:
tags:
- data-transformation
- encoding-decoding
@@ -410,6 +423,7 @@ tools:
url: https://www.velociraptor.app/
projectUrl: https://raptor.cc24.dev
license: Apache 2.0
knowledgebase:
tags:
- remote-collection
- live-forensics
@@ -442,6 +456,7 @@ tools:
url: https://github.com/google/grr
projectUrl: ''
license: Apache 2.0
knowledgebase:
tags:
- remote-forensics
- scalable-collection
@@ -473,6 +488,7 @@ tools:
url: https://arkime.com/
projectUrl: ''
license: Apache 2.0
knowledgebase:
tags:
- full-packet-capture
- pcap-indexing
@@ -503,6 +519,7 @@ tools:
url: https://www.netresec.com/?page=NetworkMiner
projectUrl: ''
license: GPL-2.0 / Commercial
knowledgebase:
tags:
- pcap-analysis
- file-extraction
@@ -533,6 +550,7 @@ tools:
https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor-kape
projectUrl: ''
license: Freeware
knowledgebase:
tags:
- triage-collection
- artifact-parsing
@@ -565,6 +583,7 @@ tools:
url: https://exiftool.org/
projectUrl: ''
license: Perl Artistic License
knowledgebase:
tags:
- metadata-extraction
- exif-analysis
@@ -594,6 +613,7 @@ tools:
url: https://www.chainalysis.com/
projectUrl: ''
license: Proprietary
knowledgebase:
tags:
- blockchain-analysis
- crypto-tracing
@@ -627,6 +647,7 @@ tools:
url: https://neo4j.com/
projectUrl: https://graph.cc24.dev
license: GPL-3.0 / Commercial
knowledgebase:
tags:
- graph-database
- relationship-analysis
@@ -658,6 +679,7 @@ tools:
url: https://qgis.org/
projectUrl: ''
license: GPL-2.0
knowledgebase:
tags:
- geospatial-analysis
- gps-visualization
@@ -675,12 +697,8 @@ tools:
kollaborative Phasen und sichere Speicherung von Beweismitteln
mit Versionierung.
domains:
- incident-response
- law-enforcement
- fraud-investigation
phases:
- collaboration
- reporting
- collaboration-general
platforms:
- Web
skillLevel: novice
@@ -688,6 +706,7 @@ tools:
url: https://nextcloud.com/
projectUrl: https://cloud.cc24.dev
license: AGPL-3.0
knowledgebase:
tags:
- file-sharing
- collaboration
@@ -708,8 +727,7 @@ tools:
- incident-response
- malware-analysis
phases:
- collaboration
- reporting
- collaboration-general
platforms:
- Web
skillLevel: beginner
@@ -717,6 +735,7 @@ tools:
url: https://gitea.io/
projectUrl: https://git.cc24.dev
license: MIT
knowledgebase:
tags:
- version-control
- code-repository
@@ -749,6 +768,7 @@ tools:
url: https://github.com/ReFirmLabs/binwalk
projectUrl: ''
license: MIT
knowledgebase:
tags:
- firmware-analysis
- file-carving
@@ -786,5 +806,5 @@ phases:
name: Analyse
- id: reporting
name: Bericht & Präsentation
- id: collaboration
- id: collaboration-general
name: Übergreifend & Kollaboration