#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

Open Cyber Threat Intelligence Platform

Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

Automated threat hunting and incident response tool for Windows Event Logs with Sigma rule integration, real-time detection, and forensic artifact…

Find, verify, and analyze leaked credentials

Open-source platform to secure and manage endpoints via MDM, patch management, software deployment, and osquery-powered visibility with compliance…

Open-source security monitoring platform for threat hunting, intrusion detection, log management, incident response, and endpoint visibility with…

Cowrie SSH/Telnet Honeypot https://docs.cowrie.org/

PowerShell-based incident response toolkit that collects 25+ forensic artifacts (processes, network connections, registry, browser history) and…

androidqf (Android Quick Forensics) helps quickly gathering forensic evidence from Android devices, in order to identify potential traces of…

Forensic collection and analysis toolkit for Android and iOS devices to identify potential compromise by known spyware using public and private…

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via…

AI-driven endpoint governance platform that monitors software usage, applies deterministic policy-based risk classification, and generates structured…

Proactive security monitoring for OpenClaw deployments. Detects ClawHavoc, AMOS stealer, CVE-2026-25253, memory poisoning, and supply chain attacks.

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Real-time Windows system monitor with advanced process, network, and disk analysis, stack trace debugging, malware detection, and service management.…