7mergen DFIR
Home Blog Cheatsheets Tools About Contact
RSS GitHub
Home Blog Cheatsheets Tools About Contact

Tools

Curated utilities grouped by category. Keep it practical.

DFIR

Velociraptor

Endpoint visibility + collection at scale (DFIR / threat hunting).

favorite
endpointcollectionhunt

KAPE

Targeted forensic collection and processing framework.

collectionwindows

Malware

Capa

Identify capabilities in malware binaries using rules.

favorite
static-analysisrules

Ghidra

Software reverse engineering suite.

redisassembler

Detection

Sigma

Generic detection rule format that can be converted to SIEM queries.

favorite
rulessiem

Network

Wireshark

Packet capture and protocol analysis.

pcapanalysis

Zeek

Network security monitor with rich logs.

nsMlogs

OSINT

Maltego

Link analysis and investigations.

graphintel

Blue Team

Sysmon

Windows system monitoring via rich event telemetry.

windowstelemetry

© 2026 7mergen

RSS GitHub LinkedIn Email