Alternatives

Linux Incident Response alternatives for AI agents.

Compare similar skills by workflow fit, trust score, quality, GitHub adoption, maintenance, and install readiness.

Current skill

Linux Incident Response

practical toolkit for cybersecurity and IT professionals. It features a detailed Linux cheatsheet for incident response

47
Quality
68
Trust
411
Stars
#1

Iris Web

Similarity 130Trust 93Excellent 100

Collaborative Incident Response platform

1.5K starsJun 8, 2026 pushdevopsPythonIncident Response
$ npx skills add dfir-iris/iris-web
#2

LinuxCatScale

Similarity 128Trust 73Needs review 51

Incident Response collection and processing scripts with automated reporting scripts

331 starsJun 25, 2024 pushdevopsShellIncident Response
$ npx skills add WithSecureLabs/LinuxCatScale
#3

Catalyst

Similarity 124Trust 88Strong 84

⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident response processes

530 starsJun 2, 2026 pushdevopsVueIncident Response
$ npx skills add SecurityBrewery/catalyst
#4

Velociraptor

Similarity 123Trust 89Excellent 100

Digging Deeper....

4.0K starsJun 16, 2026 pushdevopsGoIncident Response
$ npx skills add Velocidex/velociraptor
#5

MemProcFS Analyzer

Similarity 123Trust 82Strong 80

MemProcFS-Analyzer - Automated Forensic Analysis of Windows Memory Dumps for DFIR

720 starsMay 2, 2026 pushdevopsPowerShellIncident Response
$ npx skills add LETHAL-FORENSICS/MemProcFS-Analyzer
#6

My Arsenal Of Aws Security Tools

Similarity 123Trust 91Excellent 100

List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.

9.5K starsApr 17, 2026 pushdevopsShellIncident Response
$ npx skills add toniblyx/my-arsenal-of-aws-security-tools
#7

Sleuthkit

Similarity 123Trust 90Excellent 100

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

3.1K starsJun 12, 2026 pushdevopsCIncident Response
$ npx skills add sleuthkit/sleuthkit
#8

Cortex

Similarity 122Trust 91Excellent 100

Cortex: a Powerful Observable Analysis and Active Response Engine

1.6K starsMay 20, 2026 pushdevopsScalaIncident Response
$ npx skills add TheHive-Project/Cortex
#9

Incident Response Docs

Similarity 120Trust 91Excellent 96

PagerDuty's Incident Response Documentation.

1.0K starsApr 9, 2026 pushdevopsDockerfileIncident Response
$ npx skills add PagerDuty/incident-response-docs
#10

Dfirtrack

Similarity 120Trust 79Strong 70

DFIRTrack - The Incident Response Tracking Application

536 starsJan 13, 2026 pushdevopsPythonIncident Response
$ npx skills add dfirtrack/dfirtrack
#11

Uac

Similarity 120Trust 91Excellent 100

UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It automates the collection of artifacts from a wide range of Unix-like systems, including AIX, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris.

1.4K starsMay 28, 2026 pushdevopsShellIncident Response
$ npx skills add tclahr/uac
#12

90DaysOfDevOps

Similarity 119Trust 89Excellent 100

This repository started out as a learning in public project for myself and has now become a structured learning map for many in the community. We have 3 years under our belt covering all things DevOps, including Principles, Processes, Tooling and Use Cases surrounding this vast topic.

30K starsApr 12, 2026 pushdevopsShellKubernetes
$ npx skills add MichaelCade/90DaysOfDevOps
#13

Microsoft Eventlog Mindmap

Similarity 118Trust 89Strong 84

Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...

1.1K starsNov 8, 2025 pushdevopsIncident ResponseClaude Code
$ npx skills add mdecrevoisier/Microsoft-eventlog-mindmap
#14

Fame

Similarity 118Trust 86Excellent 87

FAME Automates Malware Evaluation

941 starsJun 13, 2026 pushdevopsPythonIncident Response
$ npx skills add certsocietegenerale/fame
#15

Wazuh Docker

Similarity 118Trust 84Excellent 97

Wazuh - Docker containers

1.1K starsJun 10, 2026 pushdevopsShellIncident Response
$ npx skills add wazuh/wazuh-docker
#16

Netshoot

Similarity 117Trust 88Excellent 100

a Docker + Kubernetes network trouble-shooting swiss-army container

11K starsApr 16, 2026 pushdevopsShellKubernetes
$ npx skills add nicolaka/netshoot

How to choose

When should you switch?

Use an alternative when it has a clearer install path, higher trust score, fresher maintenance, or better platform fit for your current agent stack. Keep Linux Incident Response if it already passes your workflow test and repository review.

Next step

Compare top candidates side by side

Open the compare page, test the install commands in a sandbox, and check each repository before using a skill in production.