Awesome Incident Response Awesome

A curated list of tools and resources for security incident response, aimed to help security analysts and DFIR teams.

Digital Forensics and Incident Response (DFIR) teams are groups of people in an organization responsible for managing the response to a security incident, including gathering evidence of the incident, remediating its effects, and implementing controls to prevent the incident from recurring in the future.

Contents

IR tools Collection

Adversary Emulation

All in one Tools

Books

Communities

Disk Image Creation Tools

Evidence Collection

Incident Management

Linux Distributions

Linux Evidence Collection

Log Analysis Tools

Memory Analysis Tools

Memory Imaging Tools

OSX Evidence Collection

Other Lists

Other Tools

Playbooks

Process Dump Tools

Sandboxing/reversing tools

Timeline tools

Videos

Windows Evidence Collection