Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Categories
  3. Security
  4. Incident Response

Incident Response

The "Awesome Incident Response" project is a curated collection of resources focused on the critical field of incident response in cybersecurity. Incident response involves the systematic approach to managing and mitigating security breaches or attacks. This list encompasses a wide range of resources, including tools for detection and analysis, frameworks for incident management, training materials, and case studies. It is designed for security professionals, IT teams, and organizations looking to enhance their incident response capabilities. By leveraging these resources, users can improve their preparedness and response strategies, ultimately strengthening their security posture against potential threats.

incident-responsecybersecuritysecurity-toolsforensicsthreat-huntingincident-managementsecurity-training
RSSView on GitHub
8.9k stars1.7k forks0 contributorsUpdated
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub

Table of Contents

23 sections · 215 projects

Adversary Emulation

9 projects
APTSimulator
APTSimulator

A Windows Batch script toolset that simulates Advanced Persistent Threat (APT) attack indicators to test security monitoring and detection capabilities.

Batchfile2,75910 months ago
Atomic Red Team
Atomic Red Team

A library of portable detection tests mapped to the MITRE ATT&CK framework for security testing.

C12,2563 days ago
AutoTTP
AutoTTP

A framework for automating offensive security testing by scripting security tool APIs like Empire and Metasploit.

Python2633 years ago
Caldera
Caldera

An automated cyber security platform for adversary emulation, red teaming, and incident response built on the MITRE ATT&CK framework.

Python7,1339 hours ago
DumpsterFire
DumpsterFire

A modular, menu-driven tool for building time-delayed, distributed security event chains for Red, Blue, and Purple Team exercises.

Python1,0386 years ago
Metta
Metta

An information security preparedness tool for adversarial simulation using Redis/Celery, Python, and Vagrant.

Python1,1467 years ago
Network Flight Simulator (flightsim)
Network Flight Simulator (flightsim)

A lightweight utility to generate malicious network traffic patterns for evaluating security controls and network visibility.

Go1,3622 years ago
Red Team Automation (RTA)
Red Team Automation (RTA)

A framework of Python scripts for blue teams to test detection capabilities against malicious tradecraft modeled after MITRE ATT&CK.

Python1,0977 years ago
RedHunt OS
RedHunt OS

A pre-configured Linux virtual machine for adversary emulation and threat hunting with attacker and defender toolkits.

1,3201 year ago

All-In-One Tools

25 projects
Belkasoft Evidence Center
belkasoft.com
CimSweep
CimSweep

A PowerShell suite for remote Windows incident response and hunting using CIM/WMI, requiring no agent deployment.

PowerShell6587 years ago
CIRTkit
CIRTkit

A unified console for digital forensics and incident response (DFIR) built on the Viper Framework.

Python1529 years ago
Cyber Triage
cybertriage.com
Dissect
Dissect

A digital forensics and incident response framework for unified analysis of forensic artifacts across disk formats, filesystems, and operating systems.

1,1304 months ago
Doorman
Doorman

An osquery fleet manager for remote configuration, distributed queries, and alerting across devices.

Python6223 years ago
FLARE VM
FLARE VM

A collection of software installation scripts for Windows that automates the setup and maintenance of a reverse engineering environment on a virtual machine.

PowerShell8,8761 month ago
Fleet device management
Fleet device management

Open-source platform for IT and security teams to manage and secure thousands of computers across diverse environments.

Go6,6265 hours ago
grr
grr

An incident response framework for remote live forensics with Python client-server architecture.

Python5,0832 months ago
IRIS
IRIS

A web-based collaborative platform for incident responders to share technical details during cybersecurity investigations.

Python1,53010 days ago
Kuiper
Kuiper

A digital forensics investigation platform for parsing, searching, visualizing evidence, and enabling team collaboration.

JavaScript8971 year ago
Limacharlie
limacharlie.io
Matano
Matano

An open source, serverless security data lake for AWS that normalizes logs, enables detection-as-code, and supports petabyte-scale threat hunting.

Rust1,6871 year ago
MozDef
MozDef

An open-source security incident response platform that automates and coordinates enterprise defense workflows.

Python2,1644 years ago
MutableSecurity
MutableSecurity

A CLI program for automating the deployment, configuration, and monitoring of cybersecurity solutions across multiple hosts.

Python503 years ago
nightHawk
nightHawk

An asynchronous forensic data presentation framework for incident response, built on Elasticsearch.

Go6086 years ago
Open Computer Forensics Architecture
sourceforge.net
osquery
osquery.io
Redline
fireeye.com
SOC Multi-tool
SOC Multi-tool

A browser extension that streamlines security investigations by providing quick lookups for IPs, domains, hashes, and other indicators.

JavaScript4211 year ago
The Sleuth Kit & Autopsy
sleuthkit.org
TheHive
thehive-project.org
Velociraptor
Velociraptor

An endpoint visibility and collection tool using the Velociraptor Query Language (VQL) for host-based state information gathering.

Go4,1183 days ago
X-Ways Forensics
x-ways.net
Zentral
Zentral

An open-source platform for unified management, security, and compliance of Apple device fleets in enterprise environments.

Python87316 hours ago

Books

12 projects
Applied Incident Response
amazon.com
Art of Memory Forensics
amazon.com
Crafting the InfoSec Playbook: Security Monitoring and Incident Response Master Plan
amazon.com
Digital Forensics and Incident Response: Incident response techniques and procedures to respond to modern cyber threats
amazon.com
Introduction to DFIR
medium.com
Incident Response & Computer Forensics, Third Edition
amazon.com
Incident Response Techniques for Ransomware Attacks
amazon.com
Incident Response with Threat Intelligence
amazon.com
Intelligence-Driven Incident Response
amazon.com
Operator Handbook: Red Team + OSINT + Blue Team Reference
amazon.com
Practical Memory Forensics
amazon.com
The Practice of Network Security Monitoring: Understanding Incident Detection and Response
amazon.com

Communities

2 projects
Digital Forensics Discord Server
discordapp.com
Slack DFIR channel
dfircommunity.slack.com

Disk Image Creation Tools

5 projects
AccessData FTK Imager
accessdata.com
Bitscout
Bitscout

A customizable live OS constructor tool written in Bash for remote forensics, malware hunting, and incident response.

Shell4801 year ago
GetData Forensic Imager
forensicimager.com
Guymager
guymager.sourceforge.net
Magnet ACQUIRE
magnetforensics.com

Related Awesome Lists

📦
Hacking

The "Awesome Hacking" project is a curated resource list designed for those interested in the field of hacking, which involves exploring and exploiting vulnerabilities in computer systems and networks. This list encompasses a wide range of categories, including penetration testing tools, ethical hacking tutorials, security research papers, and community forums. It serves as a valuable resource for beginners looking to learn the basics of cybersecurity, as well as experienced professionals seeking advanced techniques and tools. Whether you are aiming to enhance your skills or stay updated on the latest security trends, this collection offers a wealth of information to support your hacking journey.

16.1k
📦
Security

The "Awesome Security" project is a curated collection of resources focused on enhancing security practices in the digital realm. This list encompasses a wide range of categories including security tools, libraries, frameworks, tutorials, and best practices for various platforms and technologies. It is designed to benefit security professionals, developers, and system administrators alike, providing valuable insights and tools to safeguard applications and data. Whether you are a beginner looking to understand security fundamentals or an experienced practitioner seeking advanced techniques, this project offers a wealth of information to help you improve your security posture and protect your digital assets.

14.2k
📦
Malware Analysis

The "Awesome Malware Analysis" project is a curated resource list designed to assist security professionals and researchers in the field of malware analysis. Malware analysis involves examining malicious software to understand its behavior, functionality, and impact. This list includes tools for static and dynamic analysis, reverse engineering resources, malware databases, and educational materials such as tutorials and courses. It is valuable for both beginners looking to learn the basics and experienced analysts seeking advanced techniques and tools. Users can find a wealth of resources to enhance their skills and improve their malware analysis capabilities.

13.6k
📦
Web Security

The "Awesome Web Security" project is a curated collection of resources focused on the security of web applications and services. Web security encompasses practices and technologies designed to protect websites and online services from cyber threats, vulnerabilities, and attacks. This list includes tools for penetration testing, secure coding practices, frameworks, libraries, and educational materials such as articles and tutorials. It is valuable for developers, security professionals, and researchers who seek to enhance their understanding of web security and implement robust security measures. Users can find essential tools and knowledge to safeguard their web applications effectively and stay ahead of potential threats.

13.2k