A self-hosted incident response platform that automates alert handling and ticket management for security teams.
Catalyst is a self-hosted, open-source incident response platform and ticket system that helps security teams automate alert handling and incident response processes. It centralizes security events into tickets, enables task assignment and progress tracking, and provides automation capabilities through reactions to streamline investigation workflows.
Security operations teams, incident responders, and organizations needing to manage and automate their security alert and incident handling procedures.
Catalyst offers a customizable, self-hosted alternative to commercial incident response platforms, with flexible ticket management, built-in automation via reactions, and extensible fields to adapt to specific organizational needs.
⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident response processes
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.
Catalyst emphasizes minimal core ticket information with extensive customization through templates and custom fields, allowing teams to adapt it to specific incident response workflows, as per the README's philosophy.
The reactions feature provides automation with triggers (HTTP/Webhooks, Collection Hooks) and actions (Python, HTTP/Webhooks), enabling streamlined alert handling and response procedures directly from the platform.
It centralizes security events into a unified ticket system with tasks, timelines, and dashboards, offering a comprehensive view for investigations, as shown in the README's screenshot examples.
As an open-source, self-hosted platform, Catalyst gives organizations full data control and privacy, ideal for security-conscious teams without reliance on external vendors.
Deploying and maintaining Catalyst requires significant technical expertise for server setup, configuration, and ongoing updates, which can be a barrier for teams without DevOps resources.
The README only mentions HTTP/Webhooks and Python for reactions, lacking native connectors for common security tools, necessitating custom development for integration with SIEMs or other systems.
While customizable, teams must invest time in designing ticket types, reactions, and workflows from scratch, with no pre-configured templates for standard use cases like phishing or malware incidents.