7mergen DFIR
Home Blog Cheatsheets Tools About Contact
RSS GitHub
Home Blog Cheatsheets Tools About Contact

Tools

Curated utilities grouped by category. Keep it practical.

DFIR

Velociraptor

Endpoint visibility + collection at scale (DFIR / threat hunting).

favorite
endpoint collection hunt

KAPE

Targeted forensic collection and processing framework.

collection windows

Malware

Capa

Identify capabilities in malware binaries using rules.

favorite
static-analysis rules

Ghidra

Software reverse engineering suite.

re disassembler

Detection

Sigma

Generic detection rule format that can be converted to SIEM queries.

favorite
rules siem

Network

Wireshark

Packet capture and protocol analysis.

pcap analysis

Zeek

Network security monitor with rich logs.

nsM logs

OSINT

Maltego

Link analysis and investigations.

graph intel

Blue Team

Sysmon

Windows system monitoring via rich event telemetry.

windows telemetry

© 2026 7mergen

RSS GitHub LinkedIn Email