#1IR playbooks, triage, case management, evidence collection, and incident management tools.
Kitploit recommended
Kirjuri is a web application for managing cases and physical forensic evidence items.

Deploys an agent to fix CVE-2021-44228 (Log4j RCE vulnerability) in a running JVM process

Detect webshells dropped on Microsoft Exchange servers exploited through "proxylogon" group of vulnerabilites (CVE-2021-26855, CVE-2021-26857,…

Indicator of Compromise Scanner for CVE-2019-19781

PowerShell Module for managing Microsoft Defender Advanced Threat Protection

Bash-based scanner detecting indicators of compromise from CVE-2023-3519 exploitation on Citrix ADC appliances, supporting live and forensic image…

Collection of YARA signatures from individual research

Tools for remediating the recent log4j2 RCE vulnerability (CVE-2021-44228)

Automated secret and leak detection scanner for GitHub and paste sites, with heuristic filtering, IOL enrichment via Shhgit/TruffleHog, and ELK-based…

This utility can help determine if indicators of compromise (IOCs) exist in the log files of a Pulse Secure VPN Appliance for CVE-2019-11510.

A PowerShell script to identify indicators of exploitation of CVE-2021-26855, CVE-2021-26857, CVE-2021-26858, and CVE-2021-26865

Discord bot for mitigating the aCropalypse vulnerability (CVE-2023-21036, CVE-2023-28303) by retroactively deleting vulnerable images

Disables Jenkins CLI/Remoting subsystem as a mitigation against unauthenticated remote code execution vulnerabilities SECURITY-218 and SECURITY-360,…

Honeypot FTP server written in .NET Core (C#) for both Linux and Windows.

Automatic security alert response framework by AWS Serverless Application Model

Quick and dirty fix to OLE2 executing code via .hta