817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Incident Response GitHub Repositories
Explore popular GitHub repositories tagged “incident-response”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
Why is this running? Trace any process, port, container, or file back to what started it - CLI + TUI.
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
A curated list of Site Reliability and Production Engineering resources.
eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and humans via dashboard.
A curated collection of publicly available resources on how technology and tech-savvy organizations around the world practice Site Reliability Engineering (SRE)
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
A curated list of tools for incident response
Complete open-source monitoring and observability platform.
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
IntelOwl: manage your Threat Intelligence at scale
Tools and Techniques for Blue Team / Incident Response
Volatility 3.0 development
Digging Deeper....
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
SRE Agent - CNCF Sandbox Project
🕵️ OSINT Tools for gathering information and actions forensics 🕵️
Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
A list of cyber-chef recipes and curated links
Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows machines. Official Twitter/X account @PersistSniper. Made with ❤️ by @last0x00 and @dottor_morte
A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
ASN / RPKI validity / BGP stats / IPv4v6 / Prefix / URL / ASPath / Organization / IP reputation / IP geolocation / IP fingerprinting / Network recon / lookup API server / Web traceroute server
Awesome Security lists for SOC/CERT/CTI
A curated knowledge base to build, run and mature a SOC (including CSIRT).
Cortex: a Powerful Observable Analysis and Active Response Engine
GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]
Monzo's real-time incident response and reporting tool ⚡️
Collaborative Incident Response platform
A collection of postmortem templates