Clear filters 22 of 585 tools shown

Incident Response & Forensics

Solutions for responding to and investigating security incidents.

Dispatch

Dispatch

Incident Response & Forensics

All of the ad-hoc things you're doing to manage incidents today, done for you, and much more!

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Tracee

Tracee

Incident Response & Forensics

A runtime security and forensics tool for Linux environments leveraging eBPF technology.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Velociraptor

Velociraptor

Incident Response & Forensics

A powerful tool for endpoint visibility and incident response, leveraging the Velociraptor Query Language (VQL) for customizable data collection.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
Timesketch

Timesketch

Incident Response & Forensics

Collaborative forensic timeline analysis

Multi-Cloud
Open Source
Self Hosted + Cloud Options
GRR Rapid Response

GRR Rapid Response

Incident Response & Forensics

GRR Rapid Response: remote live forensics for incident response

Multi-Cloud
Open Source
Self Hosted + Cloud Options
PagerDuty Incident Response Documentation

PagerDuty Incident Response Documentation

Incident Response & Forensics

PagerDuty's Incident Response Documentation for managing and responding to major incidents.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
AWS Incident Response Playbooks

AWS Incident Response Playbooks

Incident Response & Forensics

A structured framework for incident response in AWS environments, leveraging native AWS services for log collection, threat detection, and incident management.

AWS
Open Source
Self Hosted + Cloud Options
Cloud Forensics Utils

Cloud Forensics Utils

Incident Response & Forensics

Python library to carry out DFIR analysis on the Cloud

Multi-Cloud
Open Source
Self Hosted + Cloud Options
dfTimewolf

dfTimewolf

Incident Response & Forensics

A framework for orchestrating forensic collection, processing and data export

Multi-Cloud
Open Source
Self Hosted + Cloud Options
TheHive

TheHive

Incident Response & Forensics

A scalable, open-source security incident response platform that integrates case management, task assignment, and collaboration tools.

Multi-Cloud
Open Source
Self Hosted + Cloud Options
DFIR-ORC

DFIR-ORC

Incident Response & Forensics

Forensics artefact collection tool for systems running Microsoft Windows

Multi-Cloud
Open Source
Self Hosted Only
Sparrow

Sparrow

Incident Response & Forensics

Sparrow.ps1 is a PowerShell script developed by CISA's Cloud Forensics team to detect compromised accounts and applications in Azure and Microsoft 365 environments.

Multi-Cloud
Open Source
Self Hosted Only