Incident Response Forensic Framework
The main features of biggiesmallsag/nighthawkresponse are: Incident Response Platforms.
Open-source alternatives to biggiesmallsag/nighthawkresponse include: netflix/dispatch — Dispatch is an incident response orchestration platform that automates the coordination of detection, participant… thehive-project/thehive — TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security… dfir-iris/iris-web. fireeye/flare-vm — Flare-VM is a collection of scripts and an orchestrator designed to automate the installation and configuration of a… fleetdm/fleet — Fleet is an open-source device management platform that provides centralized control over computing devices running… dfirkuiper/kuiper — Digital Forensics Investigation Platform.
Dispatch is an incident response orchestration platform that automates the coordination of detection, participant assembly, and task tracking across existing communication and project management tools. It provides a web-configurable state machine to manage incident lifecycle transitions, with template-driven incident models that define types, priorities, and severity levels. The platform enforces role-based access control to map user roles to specific actions and data access, while maintaining a database-backed audit trail of all incident events and system changes for compliance and post-incid
TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro