awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعحولكيفية ترتيب النتائجالصحافةخادم MCP
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to google/grr

Open-source alternatives to Google Grr

30 open-source projects similar to google/grr, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Google Grr alternative.

  • velocidex/velociraptorالصورة الرمزية لـ Velocidex

    Velocidex/velociraptor

    3,769عرض على GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    عرض على GitHub↗3,769
  • mozilla/mozdefالصورة الرمزية لـ mozilla

    mozilla/MozDef

    2,164عرض على GitHub↗

    DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

    Python
    عرض على GitHub↗2,164
  • withsecurelabs/chainsawالصورة الرمزية لـ WithSecureLabs

    WithSecureLabs/chainsaw

    3,446عرض على GitHub↗

    Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa

    Rustattackblueteamchainsaw
    عرض على GitHub↗3,446
  • mozilla/migالصورة الرمزية لـ mozilla

    mozilla/mig

    1,202عرض على GitHub↗

    Distributed & real time digital forensics at the speed of the cloud

    Go
    عرض على GitHub↗1,202

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Find more with AI search
  • tclahr/uacالصورة الرمزية لـ tclahr

    tclahr/uac

    1,241عرض على GitHub↗
    Shellaixcollectorcomputer-forensics
    عرض على GitHub↗1,241
  • neo23x0/lokiالصورة الرمزية لـ Neo23x0

    Neo23x0/Loki

    3,763عرض على GitHub↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Python
    عرض على GitHub↗3,763
  • invoke-ir/powerforensicsالصورة الرمزية لـ Invoke-IR

    Invoke-IR/PowerForensics

    1,435عرض على GitHub↗

    PowerForensics provides an all in one platform for live disk forensic analysis

    C#
    عرض على GitHub↗1,435
  • orlikoski/cylrالصورة الرمزية لـ orlikoski

    orlikoski/CyLR

    727عرض على GitHub↗

    CyLR - Live Response Collection Tool

    C#
    عرض على GitHub↗727
  • intezer/linux-explorerالصورة الرمزية لـ intezer

    intezer/linux-explorer

    406عرض على GitHub↗

    Easy-to-use live forensics toolbox for Linux endpoints

    HTML
    عرض على GitHub↗406
  • google/rekallالصورة الرمزية لـ google

    google/rekall

    1,998عرض على GitHub↗

    Rekall Memory Forensic Framework

    Python
    عرض على GitHub↗1,998
  • osquery/osqueryالصورة الرمزية لـ osquery

    osquery/osquery

    23,113عرض على GitHub↗

    Osquery is a unified endpoint monitoring framework that exposes operating system internals as relational tables. By representing hardware, network, and process activity as structured data, it allows users to retrieve system state and configuration information using standard SQL syntax. The system distinguishes itself through a cross-platform abstraction layer that normalizes disparate operating system interfaces into a consistent schema across Windows, macOS, and Linux. It supports both interactive local analysis via a command-line shell and distributed fleet orchestration, where recurring qu

    C++hacktoberfestintrusion-detectionmonitoring
    عرض على GitHub↗23,113
  • dfirkuiper/kuiperالصورة الرمزية لـ DFIRKuiper

    DFIRKuiper/Kuiper

    893عرض على GitHub↗

    Digital Forensics Investigation Platform

    JavaScript
    عرض على GitHub↗893
  • sleuthkit/autopsyالصورة الرمزية لـ sleuthkit

    sleuthkit/autopsy

    3,015عرض على GitHub↗

    Autopsy is a digital forensic analysis platform and evidence management suite used to process disk images and file systems. It provides a graphical interface for performing deep forensic examinations of computer hard drives to identify and extract digital artifacts for investigations. The platform is built as a Java-based forensic framework that integrates native libraries to perform direct disk image analysis. It utilizes a modular architecture, allowing for the extension of data ingestion and report generation through the use of plugins. The system manages digital evidence within a central

    Javaforensicsjava
    عرض على GitHub↗3,015
  • bypass007/emergency-response-notesالصورة الرمزية لـ Bypass007

    Bypass007/Emergency-Response-Notes

    5,551عرض على GitHub↗

    Emergency-Response-Notes is a collection of technical reference documentation and playbooks used for performing forensic analysis, incident response, intrusion identification, and malware remediation. It serves as an incident response knowledge base and an intrusion analysis framework to help identify web shells, hidden backdoors, and persistence mechanisms used during security attacks. The project utilizes a case-study-based knowledge base to map real-world attack scenarios to specific mitigation and recovery steps. It provides a digital forensics playbook and a malware remediation guide for

    عرض على GitHub↗5,551
  • netflix/dispatchالصورة الرمزية لـ Netflix

    Netflix/dispatch

    6,385عرض على GitHub↗

    Dispatch is an incident response orchestration platform that automates the coordination of detection, participant assembly, and task tracking across existing communication and project management tools. It provides a web-configurable state machine to manage incident lifecycle transitions, with template-driven incident models that define types, priorities, and severity levels. The platform enforces role-based access control to map user roles to specific actions and data access, while maintaining a database-backed audit trail of all incident events and system changes for compliance and post-incid

    Python
    عرض على GitHub↗6,385
  • aquasecurity/traceeالصورة الرمزية لـ aquasecurity

    aquasecurity/tracee

    4,377عرض على GitHub↗

    Tracee is a cloud-native runtime security and forensics tool that uses eBPF to capture system calls and kernel events in real time. It operates as a standalone binary or a Helm-deployable agent for Kubernetes, normalizing system calls, network events, and container activities into a unified event pipeline for consistent analysis. The tool distinguishes itself through policy-driven event filtering using YAML-based rules, allowing users to target specific workloads and reduce noise during monitoring. It includes built-in threat detection signatures that flag suspicious behavioral patterns witho

    Gobpfdockerebpf
    عرض على GitHub↗4,377
  • ufrisk/memprocfsالصورة الرمزية لـ ufrisk

    ufrisk/MemProcFS

    4,202عرض على GitHub↗

    MemProcFS is a volatile memory analysis tool and cross-platform memory acquisition system. It functions as a memory forensic virtual file system, mapping physical memory and kernel objects into a virtual directory structure that allows users to analyze system artifacts using standard file system tools. The project distinguishes itself by providing a virtual file system for memory forensics, enabling the browsing and querying of physical memory as read-only files and folders. It also incorporates a Yara-based memory scanner to identify malware signatures and injected code within physical memor

    C
    عرض على GitHub↗4,202
  • volatilityfoundation/volatilityالصورة الرمزية لـ volatilityfoundation

    volatilityfoundation/volatility

    7,971عرض على GitHub↗

    Volatility is a memory forensics framework and digital forensics tool designed to extract and analyze evidence from volatile computer memory dumps. It functions as a memory dump parser and analysis platform used to identify running processes, network connections, and loaded modules from a system RAM capture. The framework enables the reconstruction of system state to uncover malicious activity, such as rootkits and injected code, during malware incident response and threat hunting. It provides capabilities for digital forensic investigations to detect unauthorized access and indicators of com

    Pythonmalwarememorypython
    عرض على GitHub↗7,971
  • forensicartifacts/artifactsالصورة الرمزية لـ ForensicArtifacts

    ForensicArtifacts/artifacts

    1,240عرض على GitHub↗

    Digital Forensics artifact repository

    Python
    عرض على GitHub↗1,240
  • google/timesketchالصورة الرمزية لـ google

    google/timesketch

    3,355عرض على GitHub↗

    Collaborative forensic timeline analysis

    Python
    عرض على GitHub↗3,355
  • philhagen/sof-elkالصورة الرمزية لـ philhagen

    philhagen/sof-elk

    1,740عرض على GitHub↗

    This repository contains the configuration and support files for the SOF-ELK® VM Appliance.

    Ruby
    عرض على GitHub↗1,740
  • google/turbiniaالصورة الرمزية لـ google

    google/turbinia

    783عرض على GitHub↗
    Pythonclouddfirforensics
    عرض على GitHub↗783
  • jpcertcc/logontracerالصورة الرمزية لـ JPCERTCC

    JPCERTCC/LogonTracer

    3,136عرض على GitHub↗

    LogonTracer is a security auditing tool designed for logon analysis and forensic log auditing. It functions as a dockerized security auditor that utilizes a security event graph database to map account names and network addresses, allowing for the visualization of complex system compromise patterns and authentication paths. The system features a Sigma detection engine that scans imported event logs against standardized rule sets to identify known malicious activity. It also includes an anomalous behavior detector that applies statistical analysis, graph algorithms, and hidden Markov models to

    Pythonactive-directoryblueteamdfir
    عرض على GitHub↗3,136
  • 504ensicslabs/limeالصورة الرمزية لـ 504ensicsLabs

    504ensicsLabs/LiME

    1,995عرض على GitHub↗

    LiME (formerly DMD) is a Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, such as those powered by Android. The tool supports acquiring memory either to the file system of the device or over the network. LiME is unique in that it is the first tool that allows full memory captures from Android devices. It also minimizes its interaction between user and kernel space processes during acquisition, which allows it to produce memory captures that are more forensically sound than those of other tools designed for Linux memory acquisitio

    C
    عرض على GitHub↗1,995
  • powershellmafia/cimsweepالصورة الرمزية لـ PowerShellMafia

    PowerShellMafia/CimSweep

    658عرض على GitHub↗

    CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.

    PowerShell
    عرض على GitHub↗658
  • matanolabs/matanoالصورة الرمزية لـ matanolabs

    matanolabs/matano

    1,676عرض على GitHub↗

    Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

    Rust
    عرض على GitHub↗1,676
  • cyb3rward0g/helkالصورة الرمزية لـ Cyb3rWard0g

    Cyb3rWard0g/HELK

    3,926عرض على GitHub↗

    HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data. The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and an

    Jupyter Notebook
    عرض على GitHub↗3,926
  • ahmedkhlief/apt-hunterالصورة الرمزية لـ ahmedkhlief

    ahmedkhlief/APT-Hunter

    1,408عرض على GitHub↗

    APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

    Python
    عرض على GitHub↗1,408
  • dfir-iris/iris-webالصورة الرمزية لـ dfir-iris

    dfir-iris/iris-web

    1,393عرض على GitHub↗
    Pythoncsirt-toolingdigital-forensicsdigital-forensics-incident-response
    عرض على GitHub↗1,393
  • markbaggett/srum-dumpM

    MarkBaggett/srum-dump

    0عرض على GitHub↗

    SRUM-DUMP extracts data from the System Resource Utilization Management (SRUM) database and generates an Excel spreadsheet. This tool is invaluable for forensic investigations, as SRUM maintains records of applications that have run on a system within the last 30 days.

    عرض على GitHub↗0