incident-response
Tracked open-source repos tagged incident-response, sorted by stars.
Related topics
Topics that frequently appear alongside incident-response on the same repo.
Recent risers
Repos created in the last 90 days, tagged incident-response.
No new repos tagged with this topic in the last 90 days.
- #1
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
★ 32,040+426Star change over the last 7 days - #2
Why is this running? Trace any process, port, container, or file back to what started it - CLI + TUI.
★ 22,044+155Star change over the last 7 days - #3
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
★ 16,753+37Star change over the last 7 days - #4
A curated list of Site Reliability and Production Engineering resources.
★ 13,479+13Star change over the last 7 days - #5
eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.
★ 12,068+7Star change over the last 7 days - #6
A curated collection of publicly available resources on how technology and tech-savvy organizations around the world practice Site Reliability Engineering (SRE)
★ 9,803+2Star change over the last 7 days - #7
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
★ 9,503+1Star change over the last 7 days - #8
A curated list of tools for incident response
★ 9,370+12Star change over the last 7 days - #9★ 7,556+23Star change over the last 7 days
- #10
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
★ 4,717+6Star change over the last 7 days - #11★ 4,694+9Star change over the last 7 days
- #12
Tools and Techniques for Blue Team / Incident Response
★ 4,469+7Star change over the last 7 days - #13
Volatility 3.0 development
★ 4,367+9Star change over the last 7 days - #14
Digging Deeper....
★ 4,228+12Star change over the last 7 days - #15★ 3,784+2Star change over the last 7 days
- #16
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
★ 3,333+7Star change over the last 7 days - #17★ 3,190+26Star change over the last 7 days
- #18
The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
★ 3,141+4Star change over the last 7 days - #19★ 2,634+3Star change over the last 7 days
- #20
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
★ 2,363-22Star change over the last 7 days - #21
A list of cyber-chef recipes and curated links
★ 2,217+1Star change over the last 7 days - #22
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte
★ 2,139+0Star change over the last 7 days - #23
ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web traceroute server
★ 1,928+2Star change over the last 7 days - #24
Awesome Security lists for SOC/CERT/CTI
★ 1,896+2Star change over the last 7 days - #25
A curated knowledge base to build, run and mature a SOC (including CSIRT).
★ 1,809+0Star change over the last 7 days - #26★ 1,619+1Star change over the last 7 days
- #27
GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]
★ 1,594+2Star change over the last 7 days - #28★ 1,558+0Star change over the last 7 days
- #29★ 1,557+2Star change over the last 7 days
- #30
UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.
★ 1,441+4Star change over the last 7 days