- https://github.com/sbilly/awesome-security
- https://github.com/rshipp/awesome-malware-analysis
- https://github.com/cugu/awesome-forensics
- NIST Computer Security Incident Handling Guide (800-61r2)
- Security Policy Templates
- Jai Minton's DFIR Cheat Sheet
- CISA Incident Response Series
- s0cm0nkeys Security Reference Guide
- Google Rapid Response (GRR)
- Meerkat
- log2timeline & Plaso
- https://github.com/log2timeline/plaso
- https://github.com/mark-hallman/plaso_filters/blob/master/Plaso_Filtering_Cheat-Sheet_V1.03.pdf
- https://www.sans.org/blog/digital-forensics-sift-ing-cheating-timelines-with-log2timeline/
- https://plaso.readthedocs.io/en/latest/sources/user/Using-log2timeline.html
- Timesketch
- Autopsy
- Timeline Explorer
- apfs-fuse
- Hayabusa
- Takanjo
- SANS SEC504: Hacker Tools, Techniques, Exploits, and Incident Handling
- SANS SEC555: SIEM with Tactical Analytics
- SANS FOR508: Advanced Incident Response, Threat Hunting, and Digital Forensics