FastFinder is a lightweight tool designed for threat hunting, live forensics, and triage on both Windows and Linux platforms. It focuses on endpoint enumeration and suspicious file finding based on various criteria such as file path/name, checksums, string content match, and YARA rules. It has been tested in real cases in multiple CERT, CSIRT, and SOC use cases, with examples including real malwares and vulnerability scan examples. Compiled releases are available, but compiling from sources may be tricky due to dependencies on go-yara and CGO compilation.
Common questions about FastFinder including features, pricing, alternatives, and user reviews.
FastFinder is Fast suspicious file finder for threat hunting and live forensics. It is a Security Operations solution designed to help security teams with Triage, YARA.
FastFinder is a free Security Operations tool. This makes it accessible for organizations of all sizes, from startups to enterprises. Visit https://github.com/codeyourweb/fastfinder/ for download and installation instructions.
Popular alternatives to FastFinder include:
Compare these tools and more at https://cybersectools.com/categories/security-operations
FastFinder is for security teams and organizations that need Triage, YARA. It's particularly suitable for small to medium-sized teams looking for cost-effective solutions. Other Security Operations tools can be found at https://cybersectools.com/categories/security-operations
Managed Agentic Threat Hunting Service (IOC sweeps and hypothesis based hunting)
Expands a single malware hash into full family visibility via structural analysis.