11/12 free views
Documentation
Documentation
Incident Response & Management

awesome-incident-response

by meirwah

8.3Kstars
1.6Kforks
466watchers
Updated 8 months ago
About

A comprehensive curated list of tools and resources designed to support security analysts and DFIR teams in effective incident response and digital forensics.

A curated list of tools for incident response

Primary Use Case

This repository serves as a centralized resource for security professionals, particularly incident response and digital forensics teams, to discover, evaluate, and utilize a wide range of tools for managing security incidents. It is ideal for those looking to enhance their incident detection, evidence collection, and forensic analysis capabilities through well-organized, categorized toolsets.

Key Features
  • Curated collection of incident response and forensics tools
  • Categorized resources including adversary emulation, evidence collection, and log analysis
  • Includes all-in-one toolkits and specialized utilities for memory, disk, and process analysis
  • Provides references to books, communities, and knowledge bases for DFIR
  • Supports multiple platforms including Windows, Linux, and OSX
  • Automated URL checking for resource validity
  • Integration with MITRE ATT&CK framework for adversary emulation tools
  • Includes playbooks and videos for incident response training
Security Frameworks
Reconnaissance
Collection
Discovery
Analysis
Response
Usage Insights
  • Integrate curated adversary emulation tools with purple team exercises to validate detection and response capabilities.
  • Leverage playbooks and training videos to upskill incident response teams and reduce mean time to respond (MTTR).
  • Use categorized toolsets to automate evidence collection and forensic analysis during incident investigations.
  • Combine with SIEM and SOAR platforms to streamline log analysis and incident management workflows.
  • Regularly update the tool list and validate URLs to ensure access to the latest DFIR resources and community knowledge.

Docs Take 2 Hours. AI Takes 10 Seconds.

Ask anything about awesome-incident-response. Installation? Config? Troubleshooting? Get answers trained on real docs and GitHub issues—not generic ChatGPT fluff.

3 free chats per tool • Instant responses • No credit card

Security Profile
Red Team60%
Blue Team90%
Purple Team80%
Details
LicenseApache License 2.0
Open Issues16
Topics
incident-response
security
cybersecurity
dfir
awesome-list
awesome
list
incident-response-tooling