Skip to content
#

attack-flow

Here are 3 public repositories matching this topic...

Language: All
Filter by language

Point it at disk + memory evidence; get a correlated, ATT&CK-mapped attack timeline. Rust DFIR orchestrator: one command ingests E01/EWF/VMDK/raw + memory dumps, parses NTFS/registry/EVTX/prefetch/LNK/SRUM/browser/Amcache + memory (processes, netstat, injection), correlates into a DuckDB super-timeline, scans threat-intel, and reports.

  • Updated Jun 26, 2026
  • Rust

Improve this page

Add a description, image, and links to the attack-flow topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the attack-flow topic, visit your repo's landing page and select "manage topics."

Learn more