Home / Operations Management / Security Operations

Security Operations

Tools for security operations including incident response, threat hunting and SOC automation

Try these 133 AI Security Operations Tools

FastFinder
Free

FastFinder View FastFinder

DFIRTrack is an open source web application focused on incident response for handling major incidents with many affected systems, tracking system status, tasks, and artifacts.

FastIntercept
Free

FastIntercept View FastIntercept

A Serverless Security Orchestration Automation and Response (SOAR) Framework for AWS GuardDuty with various supported actions.

FIR (Fast Incident Response)
Free

FIR (Fast Incident Response) View FIR (Fast Incident Response)

A human risk management platform that identifies, assesses, and mitigates security risks associated with employee behavior through monitoring, targeted interventions, and comprehensive reporting.

GDPatrol
Free

GDPatrol View GDPatrol

A compilation of suggested tools for each component in a detection and response pipeline, with real-world examples, to design effective threat detection and response pipelines.

GRR Rapid Response
Free

GRR Rapid Response View GRR Rapid Response

A mature SIEM environment is critical for successful SOAR implementation.

Hardentools
Free

Hardentools View Hardentools

Automate security incident handling and facilitate real-time activities of incident handlers.

INCIDENTS
Free

INCIDENTS View INCIDENTS

Malware allows attackers to execute Windows commands from a remote environment

Incident Response Investigation System (IRIS)
Free

Incident Response Investigation System (IRIS) View Incident Response Investigation System (IRIS)

Collection of scripts and resources for DevSecOps, Security Automation and Automated Incident Response Remediation.

InvalidSign
Free

InvalidSign View InvalidSign

A comprehensive auditd configuration for Linux systems following best practices.

ir-rescue
Free

ir-rescue View ir-rescue

A collection of Cyber Incident Response Playbook Battle Cards (PBC) for combating cyber threats and attacks, following a prescriptive approach inspired by CERT Societe Generale's IRM.

IRM-2022
Free

IRM-2022 View IRM-2022

Incident response and digital forensics tool for transforming data sources and logs into graphs.

IRIS-SOAR
Free

IRIS-SOAR View IRIS-SOAR

Python command line utility for incident response in AWS

JIMI SOAR
Free

JIMI SOAR View JIMI SOAR

Detect signed malware and track stolen code-signing certificates using osquery.

Kansa
Free

Kansa View Kansa

A Live Response collection script for Incident Response that automates the collection of artifacts from various Unix-like operating systems.

LeakedIn.com
Free

LeakedIn.com View LeakedIn.com

Shuffle is a platform for automating security workflows with confidence, offering templates, collaboration tools, and a large app library.

Living Security Human Risk Management Platform
Free

Living Security Human Risk Management Platform View Living Security Human Risk Management Platform

Incident response platform for automating alert handling and incident response procedures.

Mature SIEM Environment for SOAR Implementation
Free

Mature SIEM Environment for SOAR Implementation View Mature SIEM Environment for SOAR Implementation

Catalyst is a SOAR system that automates alert handling and incident response processes, adapting to your workflows and being open source.

Megatron
Free

Megatron View Megatron

A project that uses Athena and EventBridge to investigate API activity and notify of actions for incident response and misconfiguration detection.

Microsoft Sentinel Security Playbooks
Free

Microsoft Sentinel Security Playbooks View Microsoft Sentinel Security Playbooks

Malware allows attackers to execute Windows commands from a remote environment

Morgue
Free

Morgue View Morgue

Exabeam Security Operations Platform is a cloud-native security platform that applies AI and automation to security operations workflows for threat detection, investigation, and response.

NERC Alerts
Free

NERC Alerts View NERC Alerts

An automation platform with community support and documentation for easy development.

Network Intelligence
Free

Network Intelligence View Network Intelligence

Receive important notifications and updates related to North American electric grid security.

npm Blog Archive: Plot to steal cryptocurrency foiled by the npm security team
Free

npm Blog Archive: Plot to steal cryptocurrency foiled by the npm security team View npm Blog Archive: Plot to steal cryptocurrency foiled by the npm security team

Incident response framework focused on remote live forensics