incident-response
Tracked open-source repos tagged incident-response, sorted by stars.
- #31
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
★ 1,418-1Star change over the last 7 days - #32
Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.
★ 1,373+2Star change over the last 7 days - #33★ 1,370+2Star change over the last 7 days
- #34
AttackGen is a cybersecurity incident response testing tool that leverages the power of large language models and the comprehensive MITRE ATT&CK framework. The tool generates tailored incident response scenarios based on user-selected threat actor groups and your organisation's details.
★ 1,239+1Star change over the last 7 days - #35
Wazuh - Docker containers
★ 1,173+2Star change over the last 7 days - #36
IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
★ 1,134+0Star change over the last 7 days - #37
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
★ 1,109+3Star change over the last 7 days - #38
Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
★ 1,101-1Star change over the last 7 days - #39
PagerDuty's Incident Response Documentation.
★ 1,051+2Star change over the last 7 days - #40
An ops AI Agent that understands your infrastructure, finds the root cause, and fixes it — right from Slack, Telegram, Lark or DingTalk.
★ 1,006+78Star change over the last 7 days - #41★ 946+0Star change over the last 7 days
- #42
A collection of resources for Threat Hunters
★ 918+1Star change over the last 7 days - #43
Open source templates you can use to bootstrap your security programs
★ 915+1Star change over the last 7 days - #44★ 905+1Star change over the last 7 days
- #45
Quickly Extracts IP's, Email Addresses, Hashes, Files, Credit Cards, Social Security Numbers and a lot More From Text
★ 904+2Star change over the last 7 days - #46
A repository for using osquery for incident detection and response
★ 901+1Star change over the last 7 days - #47
PowerShell Digital Forensics & Incident Response Scripts.
★ 809+0Star change over the last 7 days - #48
A concise, directive, specific, flexible, and free incident response plan template
★ 804+2Star change over the last 7 days - #49
MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
★ 761+0Star change over the last 7 days - #50★ 758+1Star change over the last 7 days
- #51
MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR
★ 735+1Star change over the last 7 days - #52★ 709+2Star change over the last 7 days
- #53
Collection of forensic tools
★ 704+2Star change over the last 7 days - #54
A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.
★ 687+3Star change over the last 7 days - #55
A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID
★ 679+3Star change over the last 7 days - #56
Awesome list of keywords and artifacts for Threat Hunting sessions
★ 673+0Star change over the last 7 days - #57
This repository provides sample templates for security playbooks against various scenarios when using Amazon Web Services.
★ 672+1Star change over the last 7 days - #58
Collection of Event ID ressources useful for Digital Forensics and Incident Response
★ 663+1Star change over the last 7 days - #59
PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform
★ 638+0Star change over the last 7 days - #60
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
★ 637+7Star change over the last 7 days