#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

A Linux version of the ProcDump Sysinternals tool
Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Investigate malicious Windows logon by visualizing and analyzing Windows event log

Autopsy® is a digital forensics platform and graphical interface to The Sleuth Kit® and other digital forensics tools. It can be used by law…

Security sensor for realtime threat detection and protection


Your Everyday Threat Intelligence

Detect Tactics, Techniques & Combat Threats

PacketFence is a fully supported, trusted, Free and Open Source network access control (NAC) solution. Boasting an impressive feature set including a…

OS X Auditor is a free Mac OS X computer forensics tool

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

Python Decoders for Common Remote Access Trojans

A resource containing all the tools each ransomware gangs uses

Microsoft Threat Intelligence Security Tools

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation.…

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

IOC and YARA-based scanner for detecting indicators of compromise via file name regex, YARA signatures, hash matching, and C2 back-connect checks on…

Real-time network diagnostics in your terminal. One command, zero config, instant visibility.