AbuseIO
StackStorm is an open-source automation platform that connects and automates DevOps workflows and integrates with existing infrastructure.
Tools for security operations including incident response, threat hunting and SOC automation
StackStorm is an open-source automation platform that connects and automates DevOps workflows and integrates with existing infrastructure.
Sample security playbooks for security automation, orchestration and response (SOAR) using Microsoft Sentinel trigger
A project that uses Athena and EventBridge to investigate API activity and notify of actions for incident response and misconfiguration detection.
Migrated Splunk SOAR Connectors to new GitHub organization for better organization and management.
AWS Community repository of custom Config rules with instructions for leveraging and developing AWS Config Rules.
A collection of incident response methodologies for various security incidents, providing easy-to-use operational best practices.
A DFIR console integrating various cybersecurity tools and frameworks for efficient incident response.
Collection of scripts and resources for DevSecOps, Security Automation and Automated Incident Response Remediation.
A public incident response process documentation used at PagerDuty
A remediation orchestration platform that consolidates security alerts, automates triage, and streamlines the remediation process across hybrid environments.
A data curation platform that automates security data collection, transformation and routing while reducing data volume and infrastructure costs.
A proof of concept for using the SSM Agent in Fargate for incident response
Detect signed malware and track stolen code-signing certificates using osquery.
DFIRTrack is an open source web application focused on incident response for handling major incidents with many affected systems, tracking system status, tasks, and artifacts.
A defense-in-depth security automation and monitoring framework utilizing threat intelligence, machine learning, and serverless technologies.
An AI-powered security operations platform that automates alert investigation, triage, and response workflows for SOC analysts.
A web collaborative platform for incident responders to share technical details during investigations, shipped in Docker containers for easy installation and upgrades.
A Serverless Security Orchestration Automation and Response (SOAR) Framework for AWS GuardDuty with various supported actions.
CimSweep is a suite of CIM/WMI-based tools for incident response and hunting operations on Windows systems without the need to deploy an agent.
Repository of playbooks, scripts, and templates for automating and orchestrating Security Operations.
StackStorm is an open-source automation platform that connects and automates DevOps workflows and integrates with existing infrastructure.
A collection of Cyber Incident Response Playbook Battle Cards (PBC) for combating cyber threats and attacks, following a prescriptive approach inspired by CERT Societe Generale's IRM.