Giter Club home page Giter Club logo

dfir-reference-frameworks's Introduction

DFIR Reference Frameworks

This repository is intended to provide a public reference to frameworks directly relevant to the DFIR community. It's common for the DFIR community to use terminology that isn't always well defined in the documentation they produce. This repository aims to help the DFIR community, and those reading information from the DFIR community, have a better understanding of defined terms and a more consistent approach to the language used in documentation.

Given the DFIR community is not a regulated industry, it's not common to find academic peer-reviewed papers for the majority of the topics below. For this reason, the Frameworks provided below are considered commonly used/accepted within the industry, or originate from well-known educational resrouces. This repository is not intended as a reference location to individual vendor methodologies. Any changes submitted need to show that the source meets these requirements.

Incident Response

Description Author Link
Identification and Prevention of Cyber Activity Lockheed Martin The Cyber Kill Chain
Adversary Tactics and Techniques Categorisation MITRE ATT&CK Matrix
Sensitive Information Sharing/Classification FIRST.org Traffic Light Protocal
Event and Incident Vocabulary Verizon The Vocabulary for Event Recording and Incident Sharing (VERIS)
Detection Indicators Usefulness David J Bianco The Pyramid of Pain
Capabilities to Defend an Organization Matt Swann The Incident Response Hierarchy of Needs
DFIR Reporting Lenny Zeltser Report Template for Threat Intelligence and Incident Response
Incident Response Framework for OT Systems Chris Sistrunk, Ken Proska, Glen Chason, Daniel Kapellmann Introducing Mandiant's Digital Forensics and Incident Response Framework for Embedded OT Systems

Malware Analysis

Description Author Link
Malware Analysis Process Lenny Zeltser How You Can Start Learning Malware Analysis
Sharing Malware Samples Lenny Zeltser How to Share Malware Samples With Other Researchers

Threat Intelligence

Description Author Link
CTI Source Analysis/Assessment Framework Sergio Caltagirone, Andrew Pendergast, Christopher Betz The Diamond Model of Intrusion Analysis
CTI Likelihood and Confidence Taxonomies MISP MISP Estimative Language
CTI Structured Language MITRE Structured Threat Information Expression (STIX™)
Transport Framework for Sharing CTI MITRE Trusted Automated Exchange of Intelligence Information (TAXII™)
Assessing CTI Feeds Value Kimberly K. Watson Assessing The Potential Value Of Cyber Threat Intelligence (CTI) Feeds

Proactive Response

Description Author Link
Modeling Security Threats Bruce Schneier Attack Trees
Theat Modelling Framework Microsoft The STRIDE Threat Model
Vulnerability Scoring Framework FIRST.org Common Vulnerability Scoring System

Threat Hunting

Description Author Link
TTP-Based Hunting Methodology MITRE TTP-Based Hunting
Cyber Threat Hunting Model Dan Gunter A Practical Model for Conducting Cyber Threat Hunting

Digital Forensics

Description Author Link

dfir-reference-frameworks's People

Contributors

joshlemon avatar randomaccess3 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.