#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

Linux kernel source tree

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3…

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Find, verify, and analyze leaked credentials

SQL powered operating system instrumentation, monitoring, and analytics.

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Curated index of incident response and DFIR tools, including memory and disk forensics, evidence collection, log analysis, playbooks, and educational…

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…

Defund the Police.


Open-source alerting engine for time-series monitoring data. Connects to Prometheus, VictoriaMetrics, ElasticSearch, and other data sources. Supports…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

Open Cyber Threat Intelligence Platform

🚦 Cachet, the open source, self-hosted status page system.

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Centralized log management platform for collecting, indexing, and analyzing streaming logs, with alerting and event correlation for security…