1,525 results for “topic:incident-response”
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
A curated list of Site Reliability and Production Engineering resources.
Cluster-wide network observability for Kubernetes. Captures L4 packets, L7 API calls, and decrypted TLS traffic using eBPF, with full Kubernetes context. Available to AI agents via MCP and human operators via dashboard.
A curated collection of publicly available resources on how technology and tech-savvy organizations around the world practice Site Reliability Engineering (SRE)
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
A curated list of tools for incident response
Complete open-source monitoring and observability platform.
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
IntelOwl: manage your Threat Intelligence at scale
Volatility 3.0 development
Tools and Techniques for Blue Team / Incident Response
TheHive is a Collaborative Case Management Platform, now distributed as a commercial version
Digging Deeper....
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
🕵️ OSINT Tools for gathering information and actions forensics 🕵️
A list of cyber-chef recipes and curated links
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte
SRE Agent - CNCF Sandbox Project
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web traceroute server
A curated knowledge base to build, run and mature a SOC (including CSIRT).
Cortex: a Powerful Observable Analysis and Active Response Engine
Monzo's real-time incident response and reporting tool ⚡️
GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]
Collaborative Incident Response platform
A collection of postmortem templates
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
ThePhish: an automated phishing email analysis tool