Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Incident Response

Incident Response

176 projects

Showing 32 of 176 projects

VolDiff
VolDiffPython

A Python script that uses Volatility to analyze malware memory footprints by comparing Windows memory images before and after infection.

#digital-forensics#security-tools#malware-analysis
Stars195
Forks45
Last commit8 years ago
dorothy2
dorothy2Ruby

A Ruby framework for automated malware and botnet analysis using sandboxed virtual machines and network traffic dissection.

#network-forensics#couchdb#botnet-analysis
Stars195
Forks33
Last commit2 years ago
AChoir
AChoirC++

A scripting framework for standardizing and automating Windows live forensic artifact acquisition using common utilities.

#digital-forensics#scripting-framework#remote-acquisition
Stars192
Forks29
Last commit4 years ago
PyrsistenceSniper
PyrsistenceSniperPython

A Python tool for offline detection of Windows persistence mechanisms in forensic collections like KAPE dumps or mounted disk images.

#digital-forensics#kape#registry-analysis
Stars191
Forks26
Last commit2 months ago
Malware Persistence
Malware Persistence

A curated collection of information and tools for detecting, analyzing, and hunting malware persistence mechanisms across operating systems.

#windows-security#malware-detection#macos-security
Stars188
Forks16
Last commit2 months ago
Phishing Intelligence Engine (PIE)
Phishing Intelligence Engine (PIE)PowerShell

An Active Defense PowerShell framework for detecting and responding to phishing attacks in Office 365 environments.

#logrhythm-integration#sandbox-analysis#active-defense
Stars180
Forks54
Last commit
Spyre
SpyreGo

A simple, self-contained modular host-based IOC scanner built around the YARA pattern matching engine.

#hacktoberfest#macosx#malware-detection
Stars179
Forks31
Last commit2 months ago
FastIR Collector Linux
FastIR Collector LinuxPython

A live forensics tool for Linux that collects system artifacts and logs them to CSV files for compromise detection.

#digital-forensics#csv-output#python2
Stars176
Forks45
Last commit5 years ago
RECmd
RECmdRebol

A command-line tool for parsing, searching, and analyzing Windows Registry hives with batch processing and forensic capabilities.

#digital-forensics#batch-processing#registry-analysis
Stars175
Forks43
Last commit1 month ago
Security Card Games
Security Card Games

A curated list of security card games and tabletop exercises for training and discussion.

#security-training#cryptography-education#education
Stars173
Forks16
Last commit1 year ago
SDLC Infrastructure Threat Framework (SITF)
SDLC Infrastructure Threat Framework (SITF)HTML

A framework for analyzing and defending against supply chain attacks targeting Software Development Lifecycle infrastructure.

#supply-chain-security#attack-framework#vcs-security
Stars165
Forks17
Last commit
Aleph
AlephCSS

An open-source malware analysis pipeline system that automates sample collection, processing, and JSON-based artifact storage.

#sample-processing#security-automation#python
Stars158
Forks55
Last commit5 years ago
InnerWarden
InnerWardenRust

An autonomous open-source security agent for Linux that detects, scores, and automatically responds to threats using eBPF, AI, and collaborative defense.

#honeypot#self-hosted-security#sigma-rules
Stars155
Forks22
Last commit1 day ago
CIRTkit
CIRTkitPython

A unified console for digital forensics and incident response (DFIR) built on the Viper Framework.

#digital-forensics#viper-framework#dfir
Stars152
Forks23
Last commit9 years ago
CIRTKit
CIRTKitPython

A unified console for digital forensics and incident response built on the Viper Framework.

#digital-forensics#viper-framework#security-automation
Stars152
Forks23
Last commit9 years ago
Invoke-LiveResponse
Invoke-LiveResponsePowerShell

A PowerShell-based live response and forensic collection tool for targeted incident response on Windows systems.

#forensic-collection#digital-forensics#liveresponse
Stars150
Forks28
Last commit4 years ago
NotifySecurity
NotifySecurityC#

Outlook add-in that enables users to report suspicious emails to security teams with one click.

#microsoft-office#phishing-reporting#security-awareness
Stars133
Forks17
Last commit3 years ago
Fileintel
FileintelPython

A modular Python tool that collects threat intelligence from multiple sources for files identified by their hash.

#nsrl#virustotal#threatcrowd
Stars123
Forks24
Last commit5 years ago
Acquire
AcquirePython

A tool to quickly gather forensic artifacts from disk images or live systems into lightweight containers for digital forensic triage.

#digital-forensics#disk-imaging#python
Stars121
Forks38
Last commit28 days ago
Anvilogic Detection Armory
Anvilogic Detection Armory

An open-source repository of cybersecurity detection rules and threat identifiers for security teams to enhance threat detection capabilities.

#security-analytics#splunk#mitre-attack
Stars119
Forks7
Last commit2 months ago
nsrllookup
nsrllookupC++

A command-line tool for digital forensics that checks file MD5 hashes against the NSRL Reference Data Set to identify known software files.

#digital-forensics#md5#nsrl
Stars115
Forks12
Last commit5 years ago
MalPipe
MalPipePython

A modular malware and IOC ingestion framework that collects, enriches, and exports threat intelligence from multiple feeds.

#security-automation#security-tools#malware-analysis
Stars110
Forks22
Last commit7 years ago
Ghost-usb
Ghost-usbC

A honeypot that emulates USB storage devices to detect and capture malware that spreads via USB propagation.

#honeypot#windows-security#malware-detection
Stars103
Forks26
Last commit11 years ago
WELA
WELAPowerShell

A PowerShell tool for auditing and configuring Windows event log settings to improve security visibility and detection capabilities.

#event-log-analysis#sigma-rules#windows-security
Stars100
Forks7
Last commit7 days ago
DATA
DATAPython

A toolkit for analyzing credential phishing sites by automating screenshot capture, file scraping, form interaction, and PDF URL extraction.

#pdf-analysis#screenshot-capture#security-automation
Stars99
Forks28
Last commit7 years ago
NotRuler
NotRulerGo

A tool for Exchange administrators to detect malicious client-side rules, VBScript forms, and custom homepages used in attacks.

#mapi#outlook-rules#security-tools
Stars96
Forks17
Last commit8 years ago
Digital Forensics Artifact Knowledge Base
Digital Forensics Artifact Knowledge BasePython

A knowledge base documenting digital forensics artifacts to help investigators understand evidence sources and their forensic significance.

#digital-forensics#evidence-collection#forensic-artifacts
Stars90
Forks15
Last commit
Squidmagic
SquidmagicPython

Analyzes web traffic via Squid proxy to detect command and control servers and malicious sites using Spamhaus data.

#python-tool#network-traffic#traffic-analysis
Stars81
Forks25
Last commit8 years ago
Detection Engineering with Splunk
Detection Engineering with Splunk

A collection of Splunk SPL queries for detecting vulnerability exploits, malware, and MITRE ATT&CK TTPs in security logs.

#text4shell#vulnerability#splunk
Stars69
Forks10
Last commit2 years ago
honeyku
honeykuPython

A Heroku-based web honeypot for creating and monitoring fake HTTP endpoints (honeytokens) to detect attackers and malicious activity.

#honeypot#honeytoken#flask
Stars65
Forks11
Last commit7 years ago
Defensomania
DefensomaniaRuby

A security incident response card game that trains defenders through fictional scenarios and activity-based gameplay.

#tabletop-game#security-training#incident-response-readiness
Stars65
Forks7
Last commit3 years ago
modpot
modpotHTML

A modular web application honeypot framework written in Go and Gin for detecting web attacks through deceptive applications.

#honeypot#web-security#cyber-threat-intelligence
Stars63
Forks2
Last commit2 years ago
PreviousPage 5 of 5

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
6 years ago
12 days ago
24 days ago
#Digital Forensics77
#Cybersecurity66
#Threat Hunting43
#Malware Analysis41
#Security Tools39
#Forensics36
#Python35
#Threat Intelligence35
#Dfir33
#Security30
#Security Automation29
#Threat Detection28