#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

Mapping Corelight or Zeek data to Elastic Common Schema logs
Horizontally scalable, multi-tenant log aggregation system that indexes labels instead of full text, integrates with Grafana, and is optimized for…

This repository provides a centralized resource for operational cyber defense and offense, compiling Theory, Tools, Operating Procedures, and…

Parses iOS and iPadOS forensic extractions into HTML, TSV, timeline, KML, and LAVA reports with modular artifact discovery and encrypted iTunes…

Your Everyday Threat Intelligence

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

Portable Linux RAM acquisition tool for forensics and incident response, capturing LiME-compatible images with optional compression and remote…

Collect, parse, normalize, aggregate, store, query, and route security telemetry data at scale using pipeline-based dataflows for threat detection…

Read-only developer endpoint scanner for on-disk package, extension, and developer-tool metadata, built to check exposure to known software…

Paperweight scans your inbox to map your digital footprint, then helps you take back control and delete your data. Local-first and open source.

Read-only AI agent that queries your cloud, code, and runtime infrastructure to surface misconfigurations, leaked secrets, and privilege escalation…

Collaborative Incident Response platform

Secure agents in seconds with permissions enforced at runtime.

A curated knowledge base to build, run and mature a SOC (including CSIRT).

eBPF-based Linux security monitor and threat hunter providing chronologically ordered, container-aware events with on-host correlation for incident…

A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

SOC detection rules and content for T1003.001 LSASS credential dumping and CVE-2021-40444 exploitation activity.

SécurixOS is a NixOS-based secure operating system tailored for small to medium-sized teams. It provides a minimal, hardened environment with strong…