Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Incident Response

Incident Response

193 projects

Showing 36 of 193 projects

Malcolm
MalcolmPython

A powerful, easily deployable network traffic analysis tool suite for PCAP files, Zeek logs, and Suricata alerts.

#suricata#opensearch-dashboards#infosec
Stars474
Forks77
Last commit2 days ago
FireEye OpenIOCs
FireEye OpenIOCs

A collection of publicly shared Indicators of Compromise (IOCs) from FireEye for threat intelligence and security research.

#malware-detection#apache-2.0#indicators-of-compromise
Stars470
Forks117
Last commit7 years ago
threat_note
threat_noteHTML

A lightweight investigation notebook for security analysts to document and track threat intelligence.

#security-analytics#security-documentation#ioc-tracking
Stars434
Forks93
Last commit2 years ago
GuardSIght Playbook Battle Cards
GuardSIght Playbook Battle Cards

A collection of prescriptive recipes for preparing and applying countermeasures against cyber threats and attacks.

#cyber-threats#playbook-battle-cards#secops
Stars434
Forks88
Last commit2 years ago
SOC Multi-tool
SOC Multi-toolJavaScript

A browser extension that streamlines security investigations by providing quick lookups for IPs, domains, hashes, and other indicators.

#security-investigation#browser-extension#ioc-analysis
Stars421
Forks56
Last commit
Cuckoo-modified
Cuckoo-modifiedPython

A modified fork of Cuckoo Sandbox with enhanced malware analysis capabilities, improved stability, and additional features.

#sandbox#behavioral-analysis#security-automation
Stars407
Forks175
Last commit
VolUtility
VolUtilityPython

A web interface for the Volatility memory forensics framework that runs plugins, stores results in MongoDB, and enables cross-plugin search.

#digital-forensics#yara-rules#security-analysis
Stars387
Forks80
Last commit6 months ago
malsub
malsubPython

A Python RESTful API framework for querying multiple online malware analysis and threat intelligence services.

#virustotal#multi-threading#security-automation
Stars366
Forks78
Last commit2 years ago
DFTimewolf
DFTimewolfPython

A framework for orchestrating forensic collection, processing, and data export through modular recipes.

#digital-forensics#workflow-automation#open-source-forensics
Stars351
Forks79
Last commit7 days ago
Cold Disk Quick Response
Cold Disk Quick ResponsePython

A forensic artifact parsing tool that quickly analyzes disk images and extracted artifacts from Windows, Linux, macOS, and Android devices.

#digital-forensics#android-forensics#disk-image-analysis
Stars345
Forks51
Last commit
Artillery
Artillery

An open-source blue team tool that protects Linux and Windows operating systems through multiple security methods.

#windows-security#security-hardening#linux-security
Stars340
Forks304
Last commit5 years ago
Linux Security and Monitoring Scripts
Linux Security and Monitoring ScriptsPython

A collection of independent Python scripts for monitoring Linux system security and investigating potential compromises.

#devops-security#configuration-audit#linux-security
Stars330
Forks46
Last commit
MFT Browser
MFT BrowserPowerShell

A Windows GUI tool that reconstructs directory trees and analyzes FILE records from NTFS Master File Table ($MFT) files.

#mft-parser#digital-forensics#disk-image-analysis
Stars330
Forks34
Last commit1 year ago
artifactcollector
artifactcollectorGo

A customizable single-binary agent for collecting forensic artifacts from Windows, macOS, and Linux systems.

#forensicartifacts#digital-forensics#macos-forensics
Stars309
Forks25
Last commit1 year ago
Malware Persistence
Malware Persistence

A curated list of tools and resources for understanding, detecting, and removing malware persistence techniques across operating systems.

#malware-detection#red-teaming#awesome-list
Stars303
Forks22
Last commit3 months ago
PowerShell implementation of Autoruns
PowerShell implementation of AutorunsPowerShell

A PowerShell module for live incident response that enumerates Windows autorun artifacts to detect persistence mechanisms used by malware and legitimate programs.

#digital-forensics#malware-detection#persistence-enumeration
Stars301
Forks52
Last commit
Detection and Response Pipeline
Detection and Response Pipeline

A curated reference hub of tools and real-world examples for designing effective threat detection and response pipelines.

#security-reference#self-hosted-security#security-automation
Stars297
Forks24
Last commit2 years ago
File Scanning Framework
File Scanning FrameworkPython

A modular, recursive file scanning framework that extends Yara signatures to extract and analyze file objects for malware analysis and intelligence.

#file-analysis#security-automation#file-scanning
Stars294
Forks46
Last commit
PSHunt
PSHuntPowerShell

A PowerShell module for remote endpoint threat hunting, scanning for indicators of compromise and collecting system state information.

#digital-forensics#windows-security#security-automation
Stars292
Forks63
Last commit9 years ago
Orochi
OrochiJavaScript

A distributed web interface for collaborative memory forensics analysis using Volatility 3.

#orochi#digital-forensics#hacktoberfest
Stars273
Forks26
Last commit1 month ago
VolatilityBot
VolatilityBotPython

An automated memory analysis tool for malware samples and memory dumps that extracts executables, processes, injections, and artifacts.

#digital-forensics#malware-analysis#automation-tool
Stars268
Forks51
Last commit5 years ago
detux
detuxPython

A multiplatform Linux sandbox for malware traffic analysis and IOC capture using QEMU emulation.

#sandbox#multi-architecture#ioc-extraction
Stars266
Forks59
Last commit4 years ago
Fastfinder
FastfinderGo

A lightweight incident response tool for rapid suspicious file discovery during threat hunting and forensic triage.

#digital-forensics#file-analysis#cli-tool
Stars259
Forks28
Last commit6 months ago
evolve
evolveJavaScript

A web-based interface for the Volatility memory forensics framework, enabling browser-based analysis of RAM dumps.

#digital-forensics#bottle-framework#ram-analysis
Stars259
Forks38
Last commit8 years ago
Tango
TangoShell

A Splunk-based platform for deploying honeypots and analyzing attacker sessions with intelligence dashboards and threat feeds.

#honeypot#splunk#sensor-management
Stars255
Forks42
Last commit7 years ago
Sandia Cyber Omni Tracker (SCOT)
Sandia Cyber Omni Tracker (SCOT)JavaScript

A cyber security incident response management system and knowledge base designed to coordinate team efforts and capture team knowledge.

#siem-alternative#snl-applications#team-coordination
Stars254
Forks44
Last commit
MAGNET DumpIt
MAGNET DumpItRust

A Linux memory acquisition tool that creates ELF core dumps compatible with gdb, crash, and drgn for incident response.

#digital-forensics#debugging-tools#elf-core-dump
Stars246
Forks28
Last commit2 years ago
PyrsistenceSniper
PyrsistenceSniperPython

A Python tool for offline detection of Windows persistence mechanisms in forensic collections like KAPE dumps or mounted disk images.

#digital-forensics#kape#registry-analysis
Stars241
Forks31
Last commit3 months ago
BoomBox
BoomBoxPowerShell

Automated deployment of a Cuckoo Sandbox malware analysis lab with Windows 10 detonation using Packer and Vagrant.

#security-lab#cuckoo-sandbox#windows-10
Stars240
Forks38
Last commit3 years ago
kube-forensics
kube-forensicsGo

A Kubernetes operator that creates checkpoint snapshots of running pods for offline forensic analysis after security incidents.

#container-security#kubernetes#crd-operator
Stars234
Forks28
Last commit8 days ago
CIFv2
CIFv2Perl

A deprecated threat intelligence platform for collecting, processing, and sharing security indicators.

#security-automation#open-source-intel#ioc-management
Stars230
Forks60
Last commit8 years ago
LogESP
LogESPPython

An open-source SIEM system built with Python Django for log management, risk assessment, and asset tracking.

#siem#vulnerability-management#nist-compliance
Stars221
Forks68
Last commit2 years ago
Hoarder
HoarderPython

A Windows artifact collection and parsing tool for targeted digital forensics and incident response investigations.

#digital-forensics#artifact-parser#disk-forensics
Stars216
Forks23
Last commit5 years ago
Lorg
LorgHTML

An advanced Apache logfile security analyzer for post-attack forensics, detecting web application attacks using multiple detection techniques.

#apache#web-security#security-analysis
Stars215
Forks48
Last commit7 years ago
DAMM
DAMMPython

An open-source memory forensics tool built on Volatility for differential analysis and data reduction in malware investigations.

#digital-forensics#volatility#python
Stars215
Forks47
Last commit9 years ago
AppCompatProcessor
AppCompatProcessorPython

A Python tool for advanced analysis of Windows AppCompat/AmCache forensic artifacts, enabling threat hunting beyond basic grep techniques.

#python-tool#malware-detection#amcache
Stars212
Forks25
Last commit4 years ago
PreviousPage 4 of 6

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
1 year ago
8 years ago
4 years ago
10 months ago
5 days ago
4 years ago
1 year ago
Next
#Digital Forensics83
#Cybersecurity71
#Security Tools46
#Malware Analysis46
#Threat Hunting44
#Python43
#Forensics39
#Threat Intelligence37
#Dfir34
#Threat Detection32
#Security31
#Security Automation30