incident-response-tooling
There are 55 repositories under incident-response-tooling topic.
meirwah/awesome-incident-response
A curated list of tools for incident response
TheHive-Project/TheHive
TheHive: a Scalable, Open Source and Free Security Incident Response Platform
cyb3rfox/Aurora-Incident-Response
Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders
dfirtrack/dfirtrack
DFIRTrack - The Incident Response Tracking Application
awslabs/aws-cloudsaga
AWS CloudSaga - Simulate security events in AWS
aws-samples/aws-health-aware
AHA is an incident management & communication framework to provide real-time alert customers when there are active AWS event(s). For customers with AWS Organizations, customers can get aggregated active account level events of all the accounts in the Organization. Customers not using AWS Organizations still benefit alerting at the account level.
vespperhq/vespper
Open-source AI copilot that lets you chat with your observability data and code 🧙♂️
netevert/pockint
A portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️
BSI-Bund/RdpCacheStitcher
RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
Correia-jpv/fucking-awesome-incident-response
A curated list of tools for incident response. With repository stars⭐ and forks🍴
EC-DIGIT-CSIRC/sysdiagnose
Forensic toolkit for iOS sysdiagnose feature
sandflysecurity/sandfly-entropyscan
Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives output with cryptographic hashes.
KaanSK/shomon
Shodan Monitoring integration for TheHive.
lawndoc/mediator
An extensible, end-to-end encrypted reverse shell that works across networks without port forwarding.
joeavanzato/RetrievIR
PowerShell script designed to help Incident Responders collect forensic evidence from local and remote Windows devices.
emrekybs/MrHandler
Linux Incident Response Reporting
urldna/urldna
The DNA test for websites
paulveillard/cybersecurity-incident-response
A collection of awesome tools, software, libraries, learning tutorials & videos, frameworks, best practices and technical resources about Incident Response & Management in Cybersecurity
MutableSecurity/mutablesecurity
CLI program for automating the setup, configuration, and use of cybersecurity solutions
HellishPn/Volatility-MM-CS
Volatility MindMap & Cheat Sheet
sandflysecurity/sandfly-file-decloak
Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.
AlecRandazzo/Packrat
Live system forensic collector
WesSec/VelociDeploy-o-Matic
Scripts to for ready-to-use Velociraptor instance deployment in Azure
availabl-co/cwtune
CLI for selecting and back-testing CloudWatch alarm configuration
aniketdvd/webams
WebAMS is an Open Source web application for reporting and resolving incidents or tickets
DFE-Digital/slack-incident-bot
A Slack app used for incident management at Department for Education Digital
NextSecurity/Cortex-Analyzers-Modified
Cortex-Analyzers Modified - SecTeam/CERT/SOC Security orchestration tools on steroids
timobrembeck/devops-chatbot
Incident management chatbot for DevOps
andygrunwald/go-incident
Go client library for accessing the Incident.io API
firew33d/awesome-incident-response
A curated list of tools for incident response
Rayraegah/postmortem
Get to the root cause of an issue, learn from it, and make sure it doesn’t happen again.
ValtteriL/Detect-Log4Shell
Powershell script to check log files for Log4Shell exploitation
giadom/Debugging_with_API_Monitor
Debug a sample in Windows using also API Monitor.
righettod/log4shell-payload-grabber
Tool to try to retrieve the java class used as dropper for the RCE in the context of log4shell vulnerability.
cyentific-rni/misp-security-playbook-object
This is the workbench for designing and updating the "security-playbook" object template for the MISP project - https://github.com/MISP/misp-objects/blob/main/objects/security-playbook/definition.json
jonasw234/systeminfo.py
systeminfo command for offline system images