<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>incident-response</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/542/feed"/>
    <updated>2026-06-28T13:42:01+00:00</updated>
    <id>https://links.biapy.com/guest/tags/542/feed</id>
            <entry>
            <id>https://links.biapy.com/links/12930</id>
            <title type="text"><![CDATA[🏥 SCRIBE]]></title>
            <link rel="alternate" href="https://github.com/nocomp/scribe" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12930"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open-source hospital crisis management platform — multi-site, multi-language.

It is a complete, mature, ready-to-deploy platform that gives crisis directors, CISOs, medical coordinators, and supervisors the structured information they need — without requiring a cloud, a vendor contract, or a six-month integration project.

Related contents:

- [\#71: Le biomédical, le Far West de la cybersécurité hospitalière | Partie 2/2 @ Cybersécurité All Day :fr:](https://cybersecuriteallday.fr/episode/le-biomedical-le-far-west-de-la-cybersecurite-hospitaliere-partie-22-71).]]>
            </summary>
            <updated>2026-06-05T06:01:12+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/12802</id>
            <title type="text"><![CDATA[VanGuard]]></title>
            <link rel="alternate" href="https://github.com/ridgelinecyberdefence/vanguard" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12802"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Enterprise Incident Response Toolkit.

 Cross-platform incident response toolkit. 28 pre-built use cases, single binary, zero install. Memory, disk, network, and cloud collection with automated timeline generation. 

Cross-platform DFIR toolkit for enterprise incident response. Velociraptor-native, air-gap compatible, portable — no installation required.

VanGuard is a self-contained incident response toolkit built in Go that gives DFIR teams a single binary for triage, threat hunting, memory forensics, disk collection, remote operations, and Velociraptor management — on both Windows and Linux, with or without network access.]]>
            </summary>
            <updated>2026-05-21T11:57:09+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/366</id>
            <title type="text"><![CDATA[Kanvas]]></title>
            <link rel="alternate" href="https://findevil.io/Kanvas-page/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/366"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Kanvas for Incident Response.

A DF/IR case management tool that provides a unified workspace for investigators enabling key workflows to be completed without switching between multiple applications.

- [Kanvas @ GitHub](https://github.com/WithSecureLabs/Kanvas).]]>
            </summary>
            <updated>2026-01-20T15:30:51+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1168</id>
            <title type="text"><![CDATA[Versus Incident]]></title>
            <link rel="alternate" href="https://versuscontrol.github.io/versus-incident/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1168"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[An open-source incident management tool supporting multi-channel alerting, customizable messages, and on-call integrations. 

- [Versus Incident @ GitHub](https://github.com/VersusControl/versus-incident).]]>
            </summary>
            <updated>2025-08-28T19:10:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1519</id>
            <title type="text"><![CDATA[Hawk]]></title>
            <link rel="alternate" href="https://github.com/T0pCyber/hawk" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1519"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Powershell Based tool for gathering information related to O365 intrusions and potential Breaches]]>
            </summary>
            <updated>2025-08-28T20:09:24+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1893</id>
            <title type="text"><![CDATA[Timesketch]]></title>
            <link rel="alternate" href="https://github.com/google/timesketch" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1893"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Collaborative forensic timeline analysis.

Timesketch is an open-source tool for collaborative forensic timeline analysis. Using sketches you and your collaborators can easily organize your timelines and analyze them all at the same time. Add meaning to your raw data with rich annotations, comments, tags and stars.]]>
            </summary>
            <updated>2025-08-28T21:12:06+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2195</id>
            <title type="text"><![CDATA[TheHive]]></title>
            <link rel="alternate" href="https://strangebee.com/thehive/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2195"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[a Scalable, Open Source and Free Security Incident Response Platform.

TheHive is a scalable 3-in-1 open source and free Security Incident Response Platform designed to make life easier for SOCs, CSIRTs, CERTs and any information security practitioner dealing with security incidents that need to be investigated and acted upon swiftly. It is the perfect companion to MISP. You can synchronize it with one or multiple MISP instances to start investigations out of MISP events. You can also export an investigation&amp;#039;s results as a MISP event to help your peers detect and react to attacks you&amp;#039;ve dealt with. Additionally, when TheHive is used in conjunction with Cortex, security analysts and researchers can easily analyze tens if not hundred of observables.

- [TheHive @ GitHub](https://github.com/TheHive-Project/TheHive).

Source: [Savez-vous ce qui est un OpenVOC ? @ Florian Dudaev&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/cyberflood_soc-voc-vulnerability-activity-7274743353609445377-8WOr/).]]>
            </summary>
            <updated>2025-08-28T22:02:29+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/2936</id>
            <title type="text"><![CDATA[SenCy-Crise :fr:]]></title>
            <link rel="alternate" href="https://www.cybermalveillance.gouv.fr/gestion-de-crise/sency-crise" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/2936"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Assistance aux victimes de cybermalveillance.

Les experts en gestion de crise cyber du Comcyber-MI appuyés par les réservistes de la gendarmerie nationale se sont associés à Cybermalveillance.gouv.fr pour accompagner les petites et moyennes entreprises, associations et collectivités à faire face aux cyberattaques.
Ce MOOC comprend des outils et conseils simples à mettre en oeuvre pour mettre en place ou améliorer le dispositif de gestion de crise cyber au sein de votre organisation.]]>
            </summary>
            <updated>2025-08-29T00:07:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3031</id>
            <title type="text"><![CDATA[DFIR-IRIS:  Incident Response Investigation System]]></title>
            <link rel="alternate" href="https://dfir-iris.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3031"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Open-Source Collaborative Incident Response Platform.
Created by incident responders for incident responders.

Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations.

- [DFIR-IRIS @ GitHub](https://github.com/dfir-iris/iris-web).]]>
            </summary>
            <updated>2025-08-29T00:21:21+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3853</id>
            <title type="text"><![CDATA[Dispatch]]></title>
            <link rel="alternate" href="https://netflix.github.io/dispatch/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3853"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Incident Management for Everyone. crisis management orchestration framework.

- [Dispatch @ GitHub](https://github.com/Netflix/dispatch).
- [Introducing Dispatch @ Netflix TechBlog](https://netflixtechblog.com/introducing-dispatch-da4b8a2a8072).]]>
            </summary>
            <updated>2025-08-29T02:38:39+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4483</id>
            <title type="text"><![CDATA[PhishTool]]></title>
            <link rel="alternate" href="https://www.phishtool.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4483"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Stop trying to avoid phishing. Choose a weapon and fight it...

PhishTool gives human analysts the power to reverse engineer phishing emails, to better defend against them. PhishTool is to phishing emails as a disassembler is to malware or a forensic toolkit is to file systems.]]>
            </summary>
            <updated>2025-08-29T04:23:35+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4735</id>
            <title type="text"><![CDATA[Forensic Miner]]></title>
            <link rel="alternate" href="https://github.com/YosfanEilay/ForensicMiner" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4735"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.

ForensicMiner, a PowerShell-based DFIR automation tool, revolutionizes the field of digital investigations. Designed for efficiency, it automates artifact and evidence collection from Windows machines. Compatibility with Flacon Crowdstrike RTR and Palo Alto Cortex XDR Live Terminal, along with its swift performance and user-friendly interface, makes ForensicMiner an indispensable asset for investigators navigating the complexities of forensic analysis. Streamlined and effective, this tool sets a new standard in the realm of digital forensics.]]>
            </summary>
            <updated>2025-08-29T05:06:58+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4739</id>
            <title type="text"><![CDATA[AWS Kill Switch]]></title>
            <link rel="alternate" href="https://github.com/secengjeff/awskillswitch" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4739"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Lambda function that streamlines containment of an AWS account compromise.

AWS Kill Switch is a Lambda function (and proof of concept client) that an organization can implement in a dedicated &amp;quot;Security&amp;quot; account to give their security engineers the ability to delete IAM roles or apply a highly restrictive service control policy (SCP) on any account in their organization.

- [AWS Kill Switch: Open-source incident response tool @ Help Net Security](https://www.helpnetsecurity.com/2023/11/27/aws-kill-switch-open-source-incident-response-tool/).]]>
            </summary>
            <updated>2025-08-29T05:07:02+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4944</id>
            <title type="text"><![CDATA[Qu1cksc0pe]]></title>
            <link rel="alternate" href="https://github.com/CYB3RMX/Qu1cksc0pe" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4944"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[All-in-One malware analysis tool.

All-in-One malware analysis tool for analyze many file types, from Windows binaries to E-Mail files.]]>
            </summary>
            <updated>2025-08-29T05:41:21+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4957</id>
            <title type="text"><![CDATA[FIRST - Forum of Incident Response and Security Teams]]></title>
            <link rel="alternate" href="https://www.first.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4957"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[FIRST is the premier organization and recognized global leader in incident response. Membership in FIRST enables incident response teams to more effectively respond to security incidents - reactive as well as proactive.

FIRST brings together a variety of computer security incident response teams from government, commercial, and educational organizations. FIRST aims to foster cooperation and coordination in incident prevention, to stimulate rapid reaction to incidents, and to promote information sharing among members and the community at large.]]>
            </summary>
            <updated>2025-08-29T05:43:18+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5010</id>
            <title type="text"><![CDATA[Velociraptor]]></title>
            <link rel="alternate" href="https://docs.velociraptor.app/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5010"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Velociraptor is an advanced digital forensic and incident response tool that enhances your visibility into your endpoints.

Velociraptor is a tool for collecting host based state information using The Velociraptor Query Language (VQL) queries.

[Velociraptor @ GitHub](https://github.com/Velocidex/velociraptor).]]>
            </summary>
            <updated>2025-08-29T05:52:16+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/5603</id>
            <title type="text"><![CDATA[Untitled Goose Tool]]></title>
            <link rel="alternate" href="https://github.com/cisagov/untitledgoosetool" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/5603"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Untitled Goose Tool is a robust and flexible hunt and incident response tool that adds novel authentication and data gathering methods in order to run a full investigation against a customer’s Azure Active Directory (AzureAD), Azure, and M365 environments. Untitled Goose Tool gathers additional telemetry from Microsoft Defender for Endpoint (MDE) and Defender for Internet of Things (IoT) (D4IoT).]]>
            </summary>
            <updated>2025-08-29T07:32:09+00:00</updated>
        </entry>
    </feed>
