Alternatives

CyberThreatHunting alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

CyberThreatHunting

A collection of resources for Threat Hunters

56
Quality
77
Trust
915
Stars
#1

Beagle

Similarity 137Trust 84Strong 72

Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.

1.3K starsDec 13, 2022 pushdevopsPythonIncident Response
$ npx skills add yampelo/beagle
#2

Dfirtrack

Similarity 134Trust 79Strong 70

DFIRTrack - The Incident Response Tracking Application

536 starsJan 13, 2026 pushdevopsPythonIncident Response
$ npx skills add dfirtrack/dfirtrack
#3

Hayabusa

Similarity 132Trust 95Excellent 100

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

3.2K starsJun 7, 2026 pushdevopsRustIncident Response
$ npx skills add Yamato-Security/hayabusa
#4

Fame

Similarity 132Trust 86Excellent 87

FAME Automates Malware Evaluation

941 starsJun 13, 2026 pushdevopsPythonIncident Response
$ npx skills add certsocietegenerale/fame
#5

Atc React

Similarity 131Trust 75Promising 55

A knowledge base of actionable Incident Response techniques

666 starsMay 31, 2022 pushdevopsPythonIncident Response
$ npx skills add atc-project/atc-react
#6

Volatility3

Similarity 129Trust 89Excellent 100

Volatility 3.0 development

4.2K starsMay 26, 2026 pushdevopsPythonIncident Response
$ npx skills add volatilityfoundation/volatility3
#7

Kanvas

Similarity 128Trust 84Strong 78

A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.

457 starsApr 29, 2026 pushdevopsPythonIncident Response
$ npx skills add WithSecureLabs/Kanvas
#8

Iris Web

Similarity 128Trust 93Excellent 100

Collaborative Incident Response platform

1.5K starsJun 8, 2026 pushdevopsPythonIncident Response
$ npx skills add dfir-iris/iris-web
#9

AiSOC

Similarity 128Trust 93Excellent 100

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.

1.4K starsJun 15, 2026 pushdevopsPythonIncident Response
$ npx skills add beenuar/AiSOC
#10

Intelmq

Similarity 127Trust 93Excellent 96

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

1.1K starsApr 28, 2026 pushdevopsPythonIncident Response
$ npx skills add certtools/intelmq
#11

My Arsenal Of Aws Security Tools

Similarity 125Trust 91Excellent 100

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

9.5K starsApr 17, 2026 pushdevopsShellIncident Response
$ npx skills add toniblyx/my-arsenal-of-aws-security-tools
#12

Catalyst

Similarity 124Trust 88Strong 84

⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident response processes

530 starsJun 2, 2026 pushdevopsVueIncident Response
$ npx skills add SecurityBrewery/catalyst
#13

Dfir Orc

Similarity 123Trust 83Strong 84

Forensics artefact collection tool for systems running Microsoft Windows

440 starsJun 16, 2026 pushdevopsC++Incident Response
$ npx skills add DFIR-ORC/dfir-orc
#14

MemProcFS Analyzer

Similarity 123Trust 82Strong 80

MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR

720 starsMay 2, 2026 pushdevopsPowerShellIncident Response
$ npx skills add LETHAL-FORENSICS/MemProcFS-Analyzer
#15

Sleuthkit

Similarity 123Trust 90Excellent 100

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

3.1K starsJun 12, 2026 pushdevopsCIncident Response
$ npx skills add sleuthkit/sleuthkit
#16

Cradle

Similarity 123Trust 85Strong 83

CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taking, automated data linking, interactive visualizations, and robust access control. Enhance your CTI workflow from analysis to reporting—all in one secure space.

344 starsMay 18, 2026 pushdevopsJavaScriptIncident Response
$ npx skills add prodaft/cradle

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep CyberThreatHunting if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.