Thursday, November 9, 2017

IR Toolkit

In 20 years of systems administration and incident response, there are a handful of tools I find myself coming back to over and over again. Naturally, the SysInternals suite is on the list, along with Wireshark and Didier Stevens PDF tools. I've also included portable installations of Python Some are useful for examining a system, others are useful for examining a suspicious file or attachment. So... I started a GitHub project to document my favorite free and/or open-source tools.

I'll bet my readers have some of their own favorites: by all means, please comment below, or submit a pull request on GitHub, and I'll update the list!