System Logs:
Windows Event Logs + Sysmon Logs
Network Logs:
Zeek Logs + Suricata alerts
Memory Logs:
Memory timeline processed via MemProcFS
Sigma Alerts:
Sigma HQ + The DFIR Report Detection Rules (Private & Public)

System Logs:
Windows Event Logs + Sysmon Logs
Network Logs:
Zeek Logs + Suricata alerts
Memory Logs:
Memory timeline processed via MemProcFS
Sigma Alerts:
Sigma HQ + The DFIR Report Detection Rules (Private & Public)

Malware samples, incident context, network logs, or decoy telemetry
Real-world visibility into active threats
Real-world visibility into active threats
Real-world visibility into active threats
© 2025 The DFIR Report. All Rights Reserved. | Privacy Policy