Dispatch is an incident response orchestration platform that automates the coordination of detection, participant assembly, and task tracking across existing communication and project management tools. It provides a web-configurable state machine to manage incident lifecycle transitions, with template-driven incident models that define types, priorities, and severity levels. The platform enforces role-based access control to map user roles to specific actions and data access, while maintaining a database-backed audit trail of all incident events and system changes for compliance and post-incid
DeepBlueCLI - a PowerShell Module for Threat Hunting via Windows Event Logs
HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data. The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and an
Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o
The main features of mitre-attack/bzar are: Forensics and Incident Response, Detection and Hunting Tools.
Open-source alternatives to mitre-attack/bzar include: sans-blue-team/deepbluecli — DeepBlueCLI - a PowerShell Module for Threat Hunting via Windows Event Logs. netflix/dispatch — Dispatch is an incident response orchestration platform that automates the coordination of detection, participant… cyb3rward0g/helk — HELK is a containerized security information and event management environment and threat hunting platform. It provides… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… ahmedkhlief/apt-hunter — APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT… abdulrhmanalfaifi/fennec.