Awesome Incident Response is a curated list of tools and resources for security incident response and digital forensics.
The list addresses the need for security analysts and DFIR teams to locate appropriate tools across the full spectrum of incident response activities. It organizes resources into categories covering the incident response lifecycle, from adversary emulation and evidence collection through memory analysis, log analysis, timeline construction, and remediation. By grouping tools by function and providing a structured reference, the list helps teams quickly identify suitable solutions for specific phases of an incident investigation.
Teams adopting this list should understand it serves as a reference guide rather than a prescriptive toolkit. It suits organizations building or expanding their incident response capabilities and needing to evaluate options across multiple tool categories. The list covers Windows, Linux, and macOS evidence collection separately, reflecting the reality that incident response often requires platform-specific tools. It includes not only technical tools but also books, communities, playbooks, and knowledge bases, making it useful for teams seeking both hands-on utilities and educational resources.
The project maintains automated URL validation to ensure listed resources remain accessible. The list is organized into distinct functional categories including all-in-one tools, disk imaging, memory imaging and analysis, log analysis, sandboxing and reversing tools, and scanner tools, allowing contributors and maintainers to systematically cover the incident response domain.