Alternatives

Hawkeye alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

Hawkeye

Windows应急响应工具---Hawkeye(鹰眼)。集Windows日志分析,进程扫描,主机信息于一体的综合应急响应分析工具

63
Quality
76
Trust
690
Stars
#1

My Arsenal Of Aws Security Tools

Similarity 125Trust 91Excellent 100

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

9.5K starsApr 17, 2026 pushdevopsShellIncident Response
$ npx skills add toniblyx/my-arsenal-of-aws-security-tools
#2

Hayabusa

Similarity 124Trust 95Excellent 100

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

3.2K starsJun 7, 2026 pushdevopsRustIncident Response
$ npx skills add Yamato-Security/hayabusa
#3

MasterParser

Similarity 122Trust 81Strong 76

MasterParser is a powerful DFIR tool designed for analyzing and parsing Linux logs

758 starsFeb 1, 2026 pushdevopsPowerShellIncident Response
$ npx skills add securityjoes/MasterParser
#4

Cortex

Similarity 122Trust 91Excellent 100

Cortex: a Powerful Observable Analysis and Active Response Engine

1.6K starsMay 20, 2026 pushdevopsScalaIncident Response
$ npx skills add TheHive-Project/Cortex
#5

Uac

Similarity 122Trust 91Excellent 100

UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.

1.4K starsMay 28, 2026 pushdevopsShellIncident Response
$ npx skills add tclahr/uac
#6

UTMStack

Similarity 117Trust 88Excellent 85

Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.

568 starsJun 16, 2026 pushdevopsTypeScriptIncident Response
$ npx skills add utmstack/UTMStack
#7

Catalyst

Similarity 116Trust 88Strong 84

⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident response processes

530 starsJun 2, 2026 pushdevopsVueIncident Response
$ npx skills add SecurityBrewery/catalyst
#8

BlueTeam Tools

Similarity 116Trust 81Strong 72

Tools and Techniques for Blue Team / Incident Response

4.1K starsMar 27, 2025 pushdevopsIncident ResponseClaude Code
$ npx skills add A-poc/BlueTeam-Tools
#9

Open Source Security Guide

Similarity 116Trust 86Strong 79

Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.

1.1K starsJun 27, 2025 pushdevopsGoIncident Response
$ npx skills add mikeroyal/Open-Source-Security-Guide
#10

Rita

Similarity 116Trust 85Excellent 85

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

578 starsJun 3, 2026 pushdevopsGoIncident Response
$ npx skills add activecm/rita
#11

Wazuh Dashboard Plugins

Similarity 116Trust 86Strong 84

Plugins for Wazuh Dashboard

512 starsJun 16, 2026 pushdevopsTypeScriptIncident Response
$ npx skills add wazuh/wazuh-dashboard-plugins
#12

Assemblyline

Similarity 116Trust 85Strong 84

AssemblyLine 4: File triage and malware analysis

508 starsJun 15, 2026 pushdevopsPythonIncident Response
$ npx skills add CybercentreCanada/assemblyline
#13

Cortex Analyzers

Similarity 116Trust 84Strong 84

Cortex Analyzers Repository

485 starsJun 11, 2026 pushdevopsPythonIncident Response
$ npx skills add TheHive-Project/Cortex-Analyzers
#14

Volatility3

Similarity 115Trust 89Excellent 100

Volatility 3.0 development

4.2K starsMay 26, 2026 pushdevopsPythonIncident Response
$ npx skills add volatilityfoundation/volatility3
#15

Velociraptor

Similarity 115Trust 89Excellent 100

Digging Deeper....

4.0K starsJun 16, 2026 pushdevopsGoIncident Response
$ npx skills add Velocidex/velociraptor
#16

Dfir Orc

Similarity 115Trust 83Strong 84

Forensics artefact collection tool for systems running Microsoft Windows

440 starsJun 16, 2026 pushdevopsC++Incident Response
$ npx skills add DFIR-ORC/dfir-orc

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Hawkeye if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.