Skip to content
#

evidence-collection

Here are 27 public repositories matching this topic...

Read-only, evidence-grade automation for FedRAMP 20x & Rev5: a TypeScript collector that captures AWS/GCP/Kubernetes config evidence for all 63 KSIs (223 requirements), benchmarks against NIST 800-53 at Low/Moderate/High, and signs it (Ed25519 + OSCAL) — plus a local multi-user tracker over the FRMR catalog.

  • Updated Jun 11, 2026
  • TypeScript

Practical labs, case studies, and investigation notes for CHFI v11 — covering digital forensics, malware forensics, incident response, evidence collection, and analysis tools.

  • Updated Aug 31, 2025

Linux Threat Hunting and Incident Response Toolkit with 8 forensic modules covering evidence collection, malware detection, persistence hunting, IOC extraction, webshell scanning, rootkit checks, and timeline reconstruction, supports chain of custody, implemented in pure Bash

  • Updated Mar 9, 2026
  • Shell

Improve this page

Add a description, image, and links to the evidence-collection topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the evidence-collection topic, visit your repo's landing page and select "manage topics."

Learn more