Tools and Techniques for Blue Team / Incident Response
$ npx skills add A-poc/BlueTeam-ToolsAlternatives
Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.
Current skill
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
Tools and Techniques for Blue Team / Incident Response
$ npx skills add A-poc/BlueTeam-ToolsOpen Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
$ npx skills add mikeroyal/Open-Source-Security-GuideDigging Deeper....
$ npx skills add Velocidex/velociraptorList of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
$ npx skills add toniblyx/my-arsenal-of-aws-security-toolsHayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
$ npx skills add Yamato-Security/hayabusaAssemblyLine 4: File triage and malware analysis
$ npx skills add CybercentreCanada/assemblylineVolatility 3.0 development
$ npx skills add volatilityfoundation/volatility3A fully configurable and extendable Bash obfuscation framework. This tool is intended to help both red team and blue team.
$ npx skills add Bashfuscator/BashfuscatorOpen-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
$ npx skills add Karib0u/rustinelThe Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
$ npx skills add sleuthkit/sleuthkitMasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs
$ npx skills add securityjoes/MasterParserCollaborative Incident Response platform
$ npx skills add dfir-iris/iris-webOpen-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.
$ npx skills add beenuar/AiSOCCortex: a Powerful Observable Analysis and Active Response Engine
$ npx skills add TheHive-Project/CortexFast and efficient osquery management
$ npx skills add jmpsec/osctrlUAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.
$ npx skills add tclahr/uacHow to choose
Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Rita if it already passes your workflow test and repository review.
Next step
Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.