AsnASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation and geolocation lookup tool / Traceroute server
DfirtrackDFIRTrack - The Incident Response Tracking Application
Vast🔮 Visibility Across Space and Time
Atc ReactA knowledge base of actionable Incident Response techniques
ScotSandia Cyber Omni Tracker (SCOT)
Dfir OrcForensics artefact collection tool for systems running Microsoft Windows
PockintA portable OSINT Swiss Army Knife for DFIR/OSINT professionals 🕵️ 🕵️ 🕵️
Litmus testDetecting ATT&CK techniques & tactics for Linux
WazuhWazuh - The Open Source Security Platform
OsctrlFast and efficient osquery management
WefflesBuild a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI
Imago ForensicsImago is a python tool that extract digital evidences from images.
Aurora Incident ResponseIncident Response Documentation made easy. Developed by Incident Responders for Incident Responders
Misp TaxonomiesTaxonomies used in MISP taxonomy system and can be used by other information sharing tool.
ThehiveTheHive: a Scalable, Open Source and Free Security Incident Response Platform
PatrowlenginesPatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform
OrianaOriana is a threat hunting tool that leverages a subset of Windows events to build relationships, calculate totals and run analytics. The results are presented in a Web layer to help defenders identify outliers and suspicious behavior on corporate environments.
SleuthkitThe Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
IntelowlIntel Owl: analyze files, domains, IPs in multiple ways from a single API at scale
Edr Testing ScriptTest the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-CradleCrafter/Invoke-DOSfuscation payloads
MthcAll-in-one bundle of MISP, TheHive and Cortex
Information Security TasksThis repository is created only for infosec professionals whom work day to day basis to equip ourself with uptodate skillset, We can daily contribute daily one hour for day to day tasks and work on problem statements daily, Please contribute by providing problem statements and solutions
PatrowldocsPatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform
SiacSIAC is an enterprise SIEM built on open-source technology.
ThreathuntThreatHunt is a PowerShell repository that allows you to train your threat hunting skills.
AwesomeA curated list of awesome things related to TheHive & Cortex
ResponseMonzo's real-time incident response and reporting tool ⚡️
Yara EndpointYara-Endpoint is a tool useful for incident response as well as anti-malware enpoint base on Yara signatures.
ScriptingPS / Bash / Python / Other scripts For FUN!
HistoricprocesstreeAn Incident Response tool that visualizes historic process execution evidence (based on Event ID 4688 - Process Creation Event) in a tree view.
Analyst CasefileMaltego CaseFile entities for information security investigations, malware analysis and incident response
BeagleBeagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
Awesome SreA curated list of Site Reliability and Production Engineering resources.
BashfuscatorA fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
CortexCortex: a Powerful Observable Analysis and Active Response Engine
FameFAME Automates Malware Evaluation
IntelmqIntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.
CyphonOpen source incident management and response platform.
OpcdeOPCDE Cybersecurity Conference Materials
HowtheysreA curated collection of publicly available resources on how technology and tech-savvy organizations around the world practice Site Reliability Engineering (SRE)
FclFCL (Fileless Command Lines) - Known command lines of fileless malicious executions
PatrowlmanagerPatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform