Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Incident Response

Incident Response

176 projects

Showing 36 of 176 projects

FireEye OpenIOCs
FireEye OpenIOCs

A collection of publicly shared Indicators of Compromise (IOCs) from FireEye for threat intelligence and security research.

#malware-detection#apache-2.0#indicators-of-compromise
Stars470
Forks117
Last commit7 years ago
Malcolm
MalcolmPython

A powerful, easily deployable network traffic analysis tool suite for PCAP files, Zeek logs, and Suricata alerts.

#suricata#opensearch-dashboards#infosec
Stars469
Forks72
Last commit7 days ago
threat_note
threat_noteHTML

A lightweight investigation notebook for security analysts to document and track threat intelligence.

#security-analytics#security-documentation#ioc-tracking
Stars435
Forks93
Last commit2 years ago
GuardSIght Playbook Battle Cards
GuardSIght Playbook Battle Cards

A collection of prescriptive recipes for preparing and applying countermeasures against cyber threats and attacks.

#cyber-threats#playbook-battle-cards#secops
Stars434
Forks86
Last commit2 years ago
SOC Multi-tool
SOC Multi-toolJavaScript

A browser extension that streamlines security investigations by providing quick lookups for IPs, domains, hashes, and other indicators.

#security-investigation#browser-extension#ioc-analysis
Stars420
Forks54
Last commit
Cuckoo-modified
Cuckoo-modifiedPython

A modified fork of Cuckoo Sandbox with enhanced malware analysis capabilities, improved stability, and additional features.

#sandbox#behavioral-analysis#security-automation
Stars407
Forks175
Last commit
VolUtility
VolUtilityPython

A web interface for the Volatility memory forensics framework that runs plugins, stores results in MongoDB, and enables cross-plugin search.

#digital-forensics#yara-rules#security-analysis
Stars386
Forks80
Last commit4 months ago
malsub
malsubPython

A Python RESTful API framework for querying multiple online malware analysis and threat intelligence services.

#virustotal#multi-threading#security-automation
Stars367
Forks78
Last commit2 years ago
DFTimewolf
DFTimewolfPython

A framework for orchestrating forensic collection, processing, and data export through modular recipes.

#digital-forensics#workflow-automation#open-source-forensics
Stars350
Forks79
Last commit5 days ago
Cold Disk Quick Response
Cold Disk Quick ResponsePython

A forensic artifact parsing tool that quickly analyzes disk images and extracted artifacts from Windows, Linux, macOS, and Android devices.

#digital-forensics#android-forensics#disk-image-analysis
Stars345
Forks51
Last commit
Artillery
Artillery

An open-source blue team tool that protects Linux and Windows operating systems through multiple security methods.

#windows-security#security-hardening#linux-security
Stars339
Forks301
Last commit5 years ago
MFT Browser
MFT BrowserPowerShell

A Windows GUI tool that reconstructs directory trees and analyzes FILE records from NTFS Master File Table ($MFT) files.

#mft-parser#digital-forensics#disk-image-analysis
Stars330
Forks34
Last commit1 year ago
Linux Security and Monitoring Scripts
Linux Security and Monitoring ScriptsPython

A collection of independent Python scripts for monitoring Linux system security and investigating potential compromises.

#devops-security#configuration-audit#linux-security
Stars329
Forks47
Last commit
artifactcollector
artifactcollectorGo

A customizable single-binary agent for collecting forensic artifacts from Windows, macOS, and Linux systems.

#forensicartifacts#digital-forensics#macos-forensics
Stars308
Forks25
Last commit1 year ago
PowerShell implementation of Autoruns
PowerShell implementation of AutorunsPowerShell

A PowerShell module for live incident response that enumerates Windows autorun artifacts to detect persistence mechanisms used by malware and legitimate programs.

#digital-forensics#malware-detection#persistence-enumeration
Stars295
Forks51
Last commit
File Scanning Framework
File Scanning FrameworkPython

A modular, recursive file scanning framework that extends Yara signatures to extract and analyze file objects for malware analysis and intelligence.

#file-analysis#security-automation#file-scanning
Stars294
Forks46
Last commit
Detection and Response Pipeline
Detection and Response Pipeline

A curated reference hub of tools and real-world examples for designing effective threat detection and response pipelines.

#security-reference#self-hosted-security#security-automation
Stars294
Forks24
Last commit2 years ago
Malware Persistence
Malware Persistence

A curated list of tools and resources for understanding, detecting, and removing malware persistence techniques across operating systems.

#malware-detection#red-teaming#awesome-list
Stars293
Forks20
Last commit2 months ago
PSHunt
PSHuntPowerShell

A PowerShell module for remote endpoint threat hunting, scanning for indicators of compromise and collecting system state information.

#digital-forensics#windows-security#security-automation
Stars291
Forks63
Last commit9 years ago
Orochi
OrochiJavaScript

A distributed web interface for collaborative memory forensics analysis using Volatility 3.

#orochi#digital-forensics#hacktoberfest
Stars269
Forks25
Last commit11 days ago
VolatilityBot
VolatilityBotPython

An automated memory analysis tool for malware samples and memory dumps that extracts executables, processes, injections, and artifacts.

#digital-forensics#malware-analysis#automation-tool
Stars268
Forks51
Last commit5 years ago
detux
detuxPython

A multiplatform Linux sandbox for malware traffic analysis and IOC capture using QEMU emulation.

#sandbox#multi-architecture#ioc-extraction
Stars266
Forks59
Last commit4 years ago
evolve
evolveJavaScript

A web-based interface for the Volatility memory forensics framework, enabling browser-based analysis of RAM dumps.

#digital-forensics#bottle-framework#ram-analysis
Stars259
Forks38
Last commit8 years ago
Tango
TangoShell

A Splunk-based platform for deploying honeypots and analyzing attacker sessions with intelligence dashboards and threat feeds.

#honeypot#splunk#sensor-management
Stars255
Forks42
Last commit7 years ago
Fastfinder
FastfinderGo

A lightweight incident response tool for rapid suspicious file discovery during threat hunting and forensic triage.

#digital-forensics#file-analysis#cli-tool
Stars255
Forks28
Last commit4 months ago
Sandia Cyber Omni Tracker (SCOT)
Sandia Cyber Omni Tracker (SCOT)JavaScript

A cyber security incident response management system and knowledge base designed to coordinate team efforts and capture team knowledge.

#siem-alternative#snl-applications#team-coordination
Stars254
Forks44
Last commit
BoomBox
BoomBoxPowerShell

Automated deployment of a Cuckoo Sandbox malware analysis lab with Windows 10 detonation using Packer and Vagrant.

#security-lab#cuckoo-sandbox#windows-10
Stars239
Forks38
Last commit3 years ago
MAGNET DumpIt
MAGNET DumpItRust

A Linux memory acquisition tool that creates ELF core dumps compatible with gdb, crash, and drgn for incident response.

#digital-forensics#debugging-tools#elf-core-dump
Stars235
Forks26
Last commit2 years ago
kube-forensics
kube-forensicsGo

A Kubernetes operator that creates checkpoint snapshots of running pods for offline forensic analysis after security incidents.

#container-security#kubernetes#crd-operator
Stars232
Forks29
Last commit1 year ago
CIFv2
CIFv2Perl

A deprecated threat intelligence platform for collecting, processing, and sharing security indicators.

#security-automation#open-source-intel#ioc-management
Stars230
Forks60
Last commit8 years ago
LogESP
LogESPPython

An open-source SIEM system built with Python Django for log management, risk assessment, and asset tracking.

#siem#vulnerability-management#nist-compliance
Stars219
Forks69
Last commit2 years ago
DAMM
DAMMPython

An open-source memory forensics tool built on Volatility for differential analysis and data reduction in malware investigations.

#digital-forensics#volatility#python
Stars214
Forks47
Last commit9 years ago
Hoarder
HoarderPython

A Windows artifact collection and parsing tool for targeted digital forensics and incident response investigations.

#digital-forensics#artifact-parser#disk-forensics
Stars214
Forks22
Last commit5 years ago
Lorg
LorgHTML

An advanced Apache logfile security analyzer for post-attack forensics, detecting web application attacks using multiple detection techniques.

#apache#web-security#security-analysis
Stars214
Forks47
Last commit7 years ago
AppCompatProcessor
AppCompatProcessorPython

A Python tool for advanced analysis of Windows AppCompat/AmCache forensic artifacts, enabling threat hunting beyond basic grep techniques.

#python-tool#malware-detection#amcache
Stars212
Forks26
Last commit4 years ago
EVTXtract
EVTXtractPython

Recovers and reconstructs fragments of EVTX log files from raw binary data, including unallocated space and memory images.

#digital-forensics#data-recovery#python
Stars211
Forks24
Last commit1 year ago
PreviousPage 4 of 5

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
1 year ago
8 years ago
4 years ago
8 months ago
2 months ago
4 years ago
1 year ago
Next
#Digital Forensics77
#Cybersecurity66
#Threat Hunting43
#Malware Analysis41
#Security Tools39
#Forensics36
#Python35
#Threat Intelligence35
#Dfir33
#Security30
#Security Automation29
#Threat Detection28