#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

Finding secrets in kernel and user memory

⭐ ⭐ Distributed tcpdump for cloud native environments ⭐ ⭐

Ransomware leak site monitoring

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Read-only PowerShell module for detecting UNC2452 and other threat actor artifacts in Azure AD, auditing federated domains, service principals,…

Automatically create YARA rules from malicious documents.

Open Cloud Security Posture Management Engine

PowerShell Module for managing Microsoft Defender Advanced Threat Protection

A user-mode application authorization system for MacOS written in Swift

A binary authorization and monitoring system for macOS

A MITM (monster-in-the-middle) detection tool. Used to build MALCOLM:

Automatic security alert response framework by AWS Serverless Application Model

By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.

EXIST is a web application for aggregating and analyzing cyber threat intelligence.

DPS' Lightweight Investigation Notebook