Alternatives

AiSOC alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

AiSOC

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.

100
Quality
93
Trust
1.4K
Stars
#1

Intelmq

Similarity 127Trust 93Excellent 96

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

1.1K starsApr 28, 2026 pushdevopsPythonIncident Response
$ npx skills add certtools/intelmq
#2

Hayabusa

Similarity 124Trust 95Excellent 100

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

3.2K starsJun 7, 2026 pushdevopsRustIncident Response
$ npx skills add Yamato-Security/hayabusa
#3

Assemblyline

Similarity 122Trust 85Strong 84

AssemblyLine 4: File triage and malware analysis

508 starsJun 15, 2026 pushdevopsPythonIncident Response
$ npx skills add CybercentreCanada/assemblyline
#4

Volatility3

Similarity 121Trust 89Excellent 100

Volatility 3.0 development

4.2K starsMay 26, 2026 pushdevopsPythonIncident Response
$ npx skills add volatilityfoundation/volatility3
#5

Iris Web

Similarity 120Trust 93Excellent 100

Collaborative Incident Response platform

1.5K starsJun 8, 2026 pushdevopsPythonIncident Response
$ npx skills add dfir-iris/iris-web
#6

Wazuh Docker

Similarity 120Trust 84Excellent 97

Wazuh - Docker containers

1.1K starsJun 10, 2026 pushdevopsShellIncident Response
$ npx skills add wazuh/wazuh-docker
#7

Bunkerweb

Similarity 118Trust 94Excellent 100

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

11K starsJun 16, 2026 pushdevopsPythonKubernetes
$ npx skills add bunkerity/bunkerweb
#8

My Arsenal Of Aws Security Tools

Similarity 117Trust 91Excellent 100

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

9.5K starsApr 17, 2026 pushdevopsShellIncident Response
$ npx skills add toniblyx/my-arsenal-of-aws-security-tools
#9

Open Source Security Guide

Similarity 116Trust 86Strong 79

Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

1.1K starsJun 27, 2025 pushdevopsGoIncident Response
$ npx skills add mikeroyal/Open-Source-Security-Guide
#10

CyberThreatHunting

Similarity 116Trust 77Promising 56

A collection of resources for Threat Hunters

915 starsOct 15, 2024 pushdevopsPythonIncident Response
$ npx skills add A3sal0n/CyberThreatHunting
#11

Incident Playbook

Similarity 116Trust 87Strong 72

GOAL: Incident Response Playbooks Mapped to MITRE Attack Tactics and Techniques. [Contributors Friendly]

1.6K starsJul 28, 2024 pushdevopsIncident ResponseClaude Code
$ npx skills add austinsonger/Incident-Playbook
#12

Fame

Similarity 116Trust 86Excellent 87

FAME Automates Malware Evaluation

941 starsJun 13, 2026 pushdevopsPythonIncident Response
$ npx skills add certsocietegenerale/fame
#13

Velociraptor

Similarity 115Trust 89Excellent 100

Digging Deeper....

4.0K starsJun 16, 2026 pushdevopsGoIncident Response
$ npx skills add Velocidex/velociraptor
#14

Rustinel

Similarity 115Trust 85Strong 83

Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.

377 starsJun 15, 2026 pushdevopsRustIncident Response
$ npx skills add Karib0u/rustinel
#15

Sleuthkit

Similarity 115Trust 90Excellent 100

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

3.1K starsJun 12, 2026 pushdevopsCIncident Response
$ npx skills add sleuthkit/sleuthkit
#16

Cradle

Similarity 115Trust 85Strong 83

CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taking, automated data linking, interactive visualizations, and robust access control. Enhance your CTI workflow from analysis to reporting—all in one secure space.

344 starsMay 18, 2026 pushdevopsJavaScriptIncident Response
$ npx skills add prodaft/cradle

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep AiSOC if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.