Incident Response & Forensics
Solutions for responding to and investigating security incidents.
Tools
Tracee
Incident Response & ForensicsA runtime security and forensics tool for Linux environments leveraging eBPF technology.
PagerDuty Postmortem Documentation
Incident Response & ForensicsPagerDuty's Public Postmortem Documentation
PagerDuty Retrospectives Documentation
Incident Response & ForensicsPagerDuty's Retrospectives Documentation provides a structured approach for teams to reflect on past incidents or projects to improve future outcomes.
Going On Call
Incident Response & ForensicsRepository for the Best Practices for On Call Teams Ops Guide
PagerDuty Automated Remediation
Incident Response & ForensicsA tool designed to reduce mean time to recover (MTTR) and alert fatigue in incident response processes through automation.
PagerDuty Full Case Ownership Documentation
Incident Response & ForensicsPagerDuty's Ops Guide for Customer Service Operations and Full Case Ownership
Sparrow
Sparrow.ps1 is a PowerShell script developed by CISA's Cloud Forensics team to detect compromised accounts and applications in Azure and Microsoft 365 environments.
Cloud Forensics Utils
Incident Response & ForensicsPython library to carry out DFIR analysis on the Cloud
aws_ir
Incident Response & ForensicsPython installable command line utility for mitigation of host and key compromises.
PagerDuty Stakeholder Communications
Incident Response & ForensicsA tool for managing internal stakeholder notifications during technical incidents, enhancing clarity and transparency.
PagerDuty Business Incident Response
Incident Response & ForensicsA structured approach to managing the business implications of technical incidents, ensuring minimal disruption to operations and maintaining customer trust.