#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended

Easy-to-use live forensics toolbox for Linux endpoints

Kernel-Mode Rootkit Hunter

CLI tools for forensic investigation of Windows artifacts

Scanners for Jar files that may be vulnerable to CVE-2021-44228

Open Cloud Security Posture Management Engine

Ransomware leak site monitoring

A tool to recover from ESXiArgs ransomware

A user-mode application authorization system for MacOS written in Swift

Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of particular use…

Differential Analysis of Malware in Memory

Automatically create YARA rules from malicious documents.

LDAP Watchdog: A real-time linux-compatible LDAP monitoring tool for detecting directory changes, providing visibility into additions, modifications,…

EXIST is a web application for aggregating and analyzing cyber threat intelligence.

Rip Raw is a small tool to analyse the memory of compromised Linux systems.

Audix is a PowerShell tool to quickly configure the Windows Event Audit Policies for security monitoring