Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Incident Response

Incident Response

176 projects

Showing 36 of 176 projects

macOS Artifact Parsing Tool (mac_apt)
macOS Artifact Parsing Tool (mac_apt)Python

A Python-based DFIR framework for extracting forensic artifacts from macOS and iOS disk images or live systems.

#apfs-parser#digital-forensics#macos-forensics
Stars1.0k
Forks125
Last commit19 days ago
Morgue
MorguePHP

A PHP-based web application for managing and tracking postmortems with pluggable features for IRC, JIRA, and timeline integration.

#jira-integration#devops-tools#php-application
Stars1.0k
Forks127
Last commit6 years ago
Awesome SOAR
Awesome SOAR

A curated awesome list of resources for Security Orchestration, Automation and Response (SOAR) technologies.

#playbooks#soar#security-automation
Stars995
Forks152
Last commit1 year ago
Raccine
RaccineC++

A Windows tool that intercepts and kills ransomware processes attempting to delete shadow copies via vssadmin and other system utilities.

#system-hardening#yara-rules#process-interception
Stars978
Forks128
Last commit2 years ago
Untitled Goose Tool
Untitled Goose ToolPython

A hunt and incident response tool for gathering forensic data from Microsoft Entra ID, Azure, M365, and Defender environments.

#cloud-forensics#azure-security#defender-for-iot
Stars955
Forks92
Last commit3 months ago
CobaltStrikeScan
CobaltStrikeScanC#

Scans files and process memory for Cobalt Strike beacons and extracts their configuration.

#cobalt-strike#windows-security#security-analysis
Stars919
Forks115
Last commit4 years ago
Kuiper
KuiperJavaScript

A digital forensics investigation platform for parsing, searching, visualizing evidence, and enabling team collaboration.

#digital-forensics#timeline-visualization#artifacts
Stars892
Forks119
Last commit1 year ago
Alerting and Detection Strategies (ADS) Framework | Palantir
Alerting and Detection Strategies (ADS) Framework | Palantir

A framework for developing rigorous, documented alerting and detection strategies to improve incident response efficacy.

#peer-review#security#mitre-attack
Stars879
Forks137
Last commit9 months ago
Munin
MuninPython

A Python utility for checking file hashes against multiple malware analysis services like VirusTotal, Hybrid Analysis, and MISP.

#virustotal#cli-tool#python
Stars853
Forks151
Last commit1 year ago
Zircolite
ZircolitePython

A standalone Python tool for applying SIGMA detection rules to EVTX, Auditd, Sysmon for Linux, and other log formats.

#sigma-rules#security#python3
Stars822
Forks114
Last commit9 days ago
Counteractive Playbooks
Counteractive PlaybooksMakefile

A concise, directive, specific, flexible, and free template for creating an incident response plan organizations will actually use.

#security-planning#playbooks#disaster-recovery
Stars782
Forks239
Last commit
OSX Security Awesome
OSX Security Awesome

A curated collection of macOS and iOS security resources including tools, research, malware analysis, and hardening guides.

#system-hardening#digital-forensics#hacking-mac
Stars781
Forks113
Last commit2 months ago
Fenrir
FenrirShell

A lightweight Bash script for scanning Linux/Unix/OSX systems for Indicators of Compromise (IOCs) without installation.

#unix#malware-detection#bash-script
Stars776
Forks114
Last commit4 years ago
HaboMalHunter
HaboMalHunterPython

An automated malware analysis tool for Linux ELF files, extracting static and dynamic features for security assessment.

#yara-rules#security#security-tools
Stars751
Forks221
Last commit3 years ago
VAST
VASTC++

A data pipeline engine for security teams to collect, transform, enrich, and route telemetry data at scale.

#stream-processing#security-analytics#siem
Stars742
Forks104
Last commit1 day ago
CyLR
CyLRC#

A cross-platform forensic artifact collection tool for NTFS file systems that minimizes host impact.

#digital-forensics#forensic-analysis#dotnet-core
Stars727
Forks95
Last commit4 years ago
RegRipper
RegRipperPerl

A Windows Registry forensics tool for extracting and analyzing data from registry hives using Perl-based plugins.

#digital-forensics#registry-analysis#security-analysis
Stars702
Forks148
Last commit12 days ago
CimSweep
CimSweepPowerShell

A PowerShell suite for remote Windows incident response and hunting using CIM/WMI, requiring no agent deployment.

#wmi-cim#windows-security#offensive-security
Stars658
Forks146
Last commit6 years ago
Awesome Event IDs
Awesome Event IDs

A curated collection of Event ID resources for digital forensics and incident response professionals.

#evtx-analysis#digital-forensics#digitalforensics
Stars656
Forks89
Last commit1 year ago
nightHawk
nightHawkGo

An asynchronous forensic data presentation framework for incident response, built on Elasticsearch.

#digital-forensics#go-application#redline-integration
Stars610
Forks123
Last commit6 years ago
iocextract
iocextractPython

A Python library and CLI for extracting and refanging defanged Indicators of Compromise (IOCs) from text.

#defang#defanging#threat-sharing
Stars580
Forks92
Last commit1 year ago
FireEye's Sunburst Countermeasures
FireEye's Sunburst CountermeasuresYARA

Open-source detection rules for identifying SolarWinds SunBurst backdoor activities and related vulnerabilities across multiple security tools.

#supply-chain-security#yara-rules#clamav-signatures
Stars562
Forks198
Last commit
docker-explorer
docker-explorerPython

A forensic tool for exploring offline Docker filesystems to analyze compromised containers.

#digital-forensics#python-tool#container-security
Stars554
Forks45
Last commit1 year ago
docker-explorer
docker-explorerPython

A forensic tool for exploring offline Docker container filesystems and metadata from disk images.

#digital-forensics#python-tool#container-security
Stars554
Forks45
Last commit1 year ago
Phantom Community Playbooks
Phantom Community PlaybooksPython

Default playbooks and custom functions for Splunk SOAR (formerly Phantom) security orchestration and automation platform.

#splunk-soar#phantom-platform#security-automation
Stars540
Forks221
Last commit2 months ago
DFIRTrack
DFIRTrackPython

A system-focused web application for tracking systems, tasks, and artifacts during major digital forensics and incident response (DFIR) investigations.

#digital-forensics#incident-response-tooling#security-tooling
Stars535
Forks87
Last commit
Catalyst
CatalystVue

A self-hosted incident response platform that automates alert handling and ticket management for security teams.

#digital-forensics#ticket-system#soar
Stars530
Forks69
Last commit6 days ago
FastIR Collector
FastIR CollectorPython

Collects Windows forensic artifacts to detect early system compromises through analysis of live data.

#digital-forensics#python-tool#csv-output
Stars520
Forks129
Last commit5 years ago
CCF-VM
CCF-VMShell

An open-source platform for collecting, processing, and analyzing forensic artifacts from macOS, Windows, and Linux systems.

#digital-forensics#dfir#forensic-analysis
Stars509
Forks79
Last commit3 years ago
Chronicle (GCP) Detection Rules
Chronicle (GCP) Detection RulesPython

A collection of example YARA-L detection rules and dashboards for Google Security Operations (SecOps).

#siem#detection-as-code#yara-l
Stars498
Forks130
Last commit13 days ago
MalConfScan
MalConfScanPython

A Volatility plugin that extracts configuration data and decoded strings from known malware families in memory images.

#digital-forensics#memory#security
Stars496
Forks69
Last commit2 years ago
PSRecon
PSReconPowerShell

A PowerShell script for live forensic data acquisition and endpoint lockdown during Windows incident response.

#windows-security#live-data-acquisition#security-automation
Stars493
Forks105
Last commit8 years ago
PSRecon
PSReconPowerShell

A PowerShell script for live forensic data acquisition and endpoint lockdown during Windows incident response.

#digital-forensics#windows-security#security-automation
Stars493
Forks105
Last commit8 years ago
ir-rescue
ir-rescueBatchfile

A Windows Batch and Unix Bash script suite for comprehensive host forensic data collection during incident response.

#batch-script#digital-forensics#sysinternals
Stars489
Forks92
Last commit5 years ago
Meerkat
MeerkatPowerShell

A PowerShell module collection for agentless artifact gathering and reconnaissance on Windows endpoints.

#digital-forensics#threat#baseline
Stars483
Forks84
Last commit1 year ago
Bitscout
BitscoutShell

A customizable live OS constructor tool written in Bash for remote forensics, malware hunting, and incident response.

#digital-forensics#bootable-media#remote-forensics
Stars480
Forks109
Last commit1 year ago
PreviousPage 3 of 5

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
2 years ago
3 years ago
4 months ago
Next
#Digital Forensics77
#Cybersecurity66
#Threat Hunting43
#Malware Analysis41
#Security Tools39
#Forensics36
#Python35
#Threat Intelligence35
#Dfir33
#Security30
#Security Automation29
#Threat Detection28