Open source incident-response projects

Every project in the registry tagged incident-response, ranked by real GitHub adoption.

projects 7 combined stars ★ 52K refresh nightly
01 witr ★ 22K

Why is this running? Trace any process, port, container, or file back to what started it - CLI + TUI.

last push1 months ago languageGo licenseApache-2.0
02 kubeshark ★ 12K

eBPF-powered network observability for Kubernetes. Indexes L4/L7 traffic with full K8s context, decrypts TLS without keys. Queryable by AI agents via MCP and hu

last push8 days ago languageGo licenseApache-2.0
03 OneUptime ★ 7.6K

Comprehensive monitoring and incident management platform

last push4 hours ago languageTypeScript licenseApache-2.0
04 Tracecat ★ 3.8K

Open source security automation platform for builders

last push3 hours ago languagePython licenseAGPL-3.0
05 holmesgpt ★ 3.4K

SRE Agent - CNCF Sandbox Project

last push7 hours ago languagePython licenseApache-2.0
06 AiSOC ★ 2.4K

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-host

last push4 days ago languagePython licenseMIT
07 MasterParser ★ 760

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

last push8 months ago languagePowerShell licenseMIT

Related tags

← all tags

Frequently asked questions

How many open source incident-response projects are there?

This registry tracks 7 projects tagged incident-response, with 52,430 GitHub stars between them. The most-adopted is witr at 22,374 stars.

Are these incident-response projects free to use?

Yes — 7 of the 7 carry an explicit open-source licence across 3 distinct licences, so there is no licence fee. Where a project also sells a hosted or enterprise version, the self-hosted path remains free.

Which incident-response project should I choose?

The list above is ranked by GitHub stars, but stars measure attention rather than fit. Check three things on each card: the licence (permissive versus copyleft), the language it is written in, and the last-push date — a high-star project that has not been pushed in a year is a liability.

Are these incident-response projects still maintained?

6 of the 7 were pushed in the last 90 days, and every card shows its exact last-push date so you can see the rest. Sort your shortlist by that date before committing to a migration.