A powerful and user-friendly browser extension that streamlines investigations for security professionals.
The main features of zdhenard42/soc-multitool are: Detection and Hunting Tools, Incident Response Platforms.
Open-source alternatives to zdhenard42/soc-multitool include: netflix/dispatch — Dispatch is an incident response orchestration platform that automates the coordination of detection, participant… powershellmafia/cimsweep — CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations… thehive-project/thehive — TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security… biggiesmallsag/nighthawkresponse — Incident Response Forensic Framework. byt3smith/cirtkit — Tools for the Computer Incident Response Team :computer:. brimsec/brim.
Dispatch is an incident response orchestration platform that automates the coordination of detection, participant assembly, and task tracking across existing communication and project management tools. It provides a web-configurable state machine to manage incident lifecycle transitions, with template-driven incident models that define types, priorities, and severity levels. The platform enforces role-based access control to map user roles to specific actions and data access, while maintaining a database-backed audit trail of all incident events and system changes for compliance and post-incid
CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.
TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro
Incident Response Forensic Framework