#incident-response (30 Repositories)
Ranked open-source repositories tagged with #incident-response, scored by pull request acceptance likelihood and maintainer engagement velocity.
20.1%
25.7h
30 repositories tagged #incident-response
Karib0u/rustinel
Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
Velocidex/velociraptor
Digging Deeper....
OneUptime/oneuptime
Complete open-source monitoring and observability platform.
jmpsec/osctrl
Fast and efficient osquery management
Vigil-SOC/vigil
Vigil: the open source AI SOC (agentic SOC). 13 specialized AI agents, 30+ MCP integrations, 7,200+ detection rules. Apache 2.0.
sleuthkit/sleuthkit
The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
tclahr/uac
UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.
Neo23x0/Loki-RS
🐍 High-performance, multi-threaded YARA & IOC scanner
meirwah/awesome-incident-response
A curated list of tools for incident response
mrwadams/attackgen
AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tailored incident response scenarios based on user-selected threat actor groups and your organisation's details.
TheHive-Project/TheHive
TheHive is a Collaborative Case Management Platform, now distributed as a commercial version
upgundecha/howtheysre
A curated collection of publicly available resources on how technology and tech-savvy organizations around the world practice Site Reliability Engineering (SRE)
toniblyx/my-arsenal-of-aws-security-tools
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
Bashfuscator/Bashfuscator
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
0x4D31/awesome-threat-detection
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
jepayneMSFT/WEFFLES
Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI
cgosec/Blauhaunt
A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you come from where did you go) in Security Incidents and Threat Hunts
darkquasar/AzureHunter
A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365
LETHAL-FORENSICS/Collect-MemoryDump
Collect-MemoryDump - Automated Creation of Windows Memory Snapshots for DFIR
DFIR-ORC/dfir-orc
Forensics artefact collection tool for systems running Microsoft Windows
incidentbot/incidentbot
The Open Source Incident Management Framework
eshlomo1/Microsoft-Sentinel-SecOps
Microsoft Sentinel SOC Operations
WithSecureLabs/LinuxCatScale
Incident Response collection and processing scripts with automated reporting scripts
bb1nfosec/Information-Security-Tasks
This repository is created only for infosec professionals whom work day to day basis to equip ourself with uptodate skillset, We can daily contribute daily one hour for day to day tasks and work on problem statements daily, Please contribute by providing problem statements and solutions
joeavanzato/Trawler
PowerShell script helping Incident Responders discover potential adversary persistence mechanisms.
LearningKijo/SecurityResearcher-Note
Cover various security approaches to attack techniques and also provides new discoveries about security breaches.
BSI-Bund/RdpCacheStitcher
RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
InfosecHouse/InfosecHouse
Tools & Resources for Cyber Security Operations
hevnsnt/Awesome_Incident_Response
Awesome Incident Response
prodaft/cradle
CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taking, automated data linking, interactive visualizations, and robust access control. Enhance your CTI workflow from analysis to reporting—all in one secure space.