Incident Response & Forensics
Solutions for responding to and investigating security incidents.
Dispatch
All of the ad-hoc things you're doing to manage incidents today, done for you, and much more!
Tracee
A runtime security and forensics tool for Linux environments leveraging eBPF technology.
Velociraptor
A powerful tool for endpoint visibility and incident response, leveraging the Velociraptor Query Language (VQL) for customizable data collection.
Timesketch
Collaborative forensic timeline analysis
GRR Rapid Response
GRR Rapid Response: remote live forensics for incident response
PagerDuty Incident Response Documentation
PagerDuty's Incident Response Documentation for managing and responding to major incidents.
AWS Incident Response Playbooks
A structured framework for incident response in AWS environments, leveraging native AWS services for log collection, threat detection, and incident management.
Cloud Forensics Utils
Python library to carry out DFIR analysis on the Cloud
dfTimewolf
A framework for orchestrating forensic collection, processing and data export
TheHive
A scalable, open-source security incident response platform that integrates case management, task assignment, and collaboration tools.
DFIR-ORC
Forensics artefact collection tool for systems running Microsoft Windows
Sparrow
Sparrow.ps1 is a PowerShell script developed by CISA's Cloud Forensics team to detect compromised accounts and applications in Azure and Microsoft 365 environments.