Back to Topics Directory
Topic Hub

#incident-response (30 Repositories)

Ranked open-source repositories tagged with #incident-response, scored by pull request acceptance likelihood and maintainer engagement velocity.

Topic Avg Merge Rate

20.1%

Avg Review Latency

25.7h

Filter by language

30 repositories tagged #incident-response

S TierRust 458 1 GFIs

Karib0u/rustinel

Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

95.7%
Merge Rate
11h
First Review
100%
1st-Timers
3
Maintainers
A TierGo 4.2k

Velocidex/velociraptor

Digging Deeper....

92.5%
Merge Rate
10h
First Review
100%
1st-Timers
10
Maintainers
A TierTypeScript 7.5k 1 GFIs

OneUptime/oneuptime

Complete open-source monitoring and observability platform.

77.0%
Merge Rate
1d
First Review
70%
1st-Timers
18
Maintainers
B TierGo 517

jmpsec/osctrl

Fast and efficient osquery management

98.3%
Merge Rate
7d
First Review
60%
1st-Timers
0
Maintainers
A TierPython 261 1 GFIs

Vigil-SOC/vigil

Vigil: the open source AI SOC (agentic SOC). 13 specialized AI agents, 30+ MCP integrations, 7,200+ detection rules. Apache 2.0.

66.7%
Merge Rate
14h
First Review
60%
1st-Timers
14
Maintainers
B TierC 3.1k

sleuthkit/sleuthkit

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

75.0%
Merge Rate
5h
First Review
0%
1st-Timers
1
Maintainers
B TierShell 1.4k

tclahr/uac

UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.

50.0%
Merge Rate
4d
First Review
0%
1st-Timers
1
Maintainers
C TierRust 348

Neo23x0/Loki-RS

🐍 High-performance, multi-threaded YARA & IOC scanner

23.8%
Merge Rate
4d
First Review
0%
1st-Timers
1
Maintainers
C TierMulti-language 9.4k

meirwah/awesome-incident-response

A curated list of tools for incident response

25.0%
Merge Rate
14d
First Review
0%
1st-Timers
1
Maintainers
D TierPython 1.2k

mrwadams/attackgen

AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tailored incident response scenarios based on user-selected threat actor groups and your organisation's details.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
1
Maintainers
D TierScala 3.9k

TheHive-Project/TheHive

TheHive is a Collaborative Case Management Platform, now distributed as a commercial version

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierJavaScript 9.8k

upgundecha/howtheysre

A curated collection of publicly available resources on how technology and tech-savvy organizations around the world practice Site Reliability Engineering (SRE)

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierShell 9.5k

toniblyx/my-arsenal-of-aws-security-tools

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 2.0k

Bashfuscator/Bashfuscator

A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierMulti-language 4.7k

0x4D31/awesome-threat-detection

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 202

jepayneMSFT/WEFFLES

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierJavaScript 188

cgosec/Blauhaunt

A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 795

darkquasar/AzureHunter

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 265

LETHAL-FORENSICS/Collect-MemoryDump

Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierC++ 447

DFIR-ORC/dfir-orc

Forensics artefact collection tool for systems running Microsoft Windows

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 165

incidentbot/incidentbot

The Open Source Incident Management Framework

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 267

eshlomo1/Microsoft-Sentinel-SecOps

Microsoft Sentinel SOC Operations

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierShell 340

WithSecureLabs/LinuxCatScale

Incident Response collection and processing scripts with automated reporting scripts

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 186

bb1nfosec/Information-Security-Tasks

This repository is created only for infosec professionals whom work day to day basis to equip ourself with uptodate skillset, We can daily contribute daily one hour for day to day tasks and work on problem statements daily, Please contribute by providing problem statements and solutions

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 340

joeavanzato/Trawler

PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 489

LearningKijo/SecurityResearcher-Note

Cover various security approaches to attack techniques and also provides new discoveries about security breaches.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierC++ 332

BSI-Bund/RdpCacheStitcher

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierHTML 313

InfosecHouse/InfosecHouse

Tools & Resources for Cyber Security Operations

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 295

hevnsnt/Awesome_Incident_Response

Awesome Incident Response

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierJavaScript 344

prodaft/cradle

CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taking, automated data linking, interactive visualizations, and robust access control. Enhance your CTI workflow from analysis to reporting—all in one secure space.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
Best Incident-response Open Source Repositories & C-Rank™ | GetMerged