#incident-response
GitHub repositories that have self-applied the topic "incident-response" — a creator-tagged metadata that surfaces how AI projects describe themselves.
REPOS Repos for #incident-response (top 15 by stars)
The self-improving SRE agent
TimothyVang/verdict-dfirVERDICT — a DFIR agent (Claude Code as the engine) that produces a signed, offline-verifiable verdict. SANS Find Evil! 2026.
everywan-dev/claude-code-engineeringTurn Claude Code into a team that has to prove it. 44 skills, 8 review agents, a validation router and a knowledge layer where nothing is claimed without a check that could have failed.
jacobideji/aiiroverlayAI IR Overlay™ — practical incident response framework for AI agents in production. Built on NIST SP 800-61 r3, mapped to NIST AI RMF, NIST CSF 2.0, OWASP Top 10 for Agentic Applications 2026, ISO/IEC 42001, EU AI Act.
canyang25/AutoSREAn autonomous, LLM-powered SRE agent that takes production incidents from alert to fix/pulls metrics and logs, diagnoses the root cause, runs remediation, and writes the incident report.
MerlijnW70/solana-breakglass-skillThe Solana emergency copilot — evidence-first, read-only incident triage for failed transactions, drains, compromised authorities, RPC issues & frontend compromise. Never moves funds. MIT.
sunnnn2005/signalroot-agentLocal-first incident triage agent with typed tools, weighted evidence, and structured root-cause reports.
Hal-Hanami/incident-triage-agentRead-only first-pass incident triage on the Claude Agent SDK + MCP: classifies an alert, retrieves the matching runbook, and proposes a cited first response — or abstains to a human. Measured over four runs: 100% abstention with 0 missed escalations, ~$0.014 per incident.
natalimuca/SOCtriageLLM alert triage over a live Wazuh SIEM, scored against a labelled corpus and a threshold baseline
Mossab28/nightshiftThe on-call data team that gets smarter every night. Claude agents on DataHub: incidents resolved, postmortems remembered in the graph itself.
Bobcatsfan33/loomdbAn agent-native database. Sessions are branches an agent can fork, merge, and rewind; every write records what it was derived from; and taint-and-recall tells you exactly what a poisoned input contaminated. Built on substrate.
markarif/Week-10-Final-Capstone-Project-ARIA-Automated-Response-Intelligence-Analyst-Production-grade AI incident response system built on n8n. 3 workflows, human approval gate, dual-model fallback, and 23-column governance audit trail.
itsbotandme/dfir-attck-ctfsBrowser-playable DFIR CTF labs organised by MITRE ATT&CK Enterprise tactics. Self-contained HTML, no agent required at runtime.
coroot/rca-labA Kubernetes lab that reproduces real production incidents on a live, instrumented microservice stack — for testing root-cause-analysis tools and agents.
WooYoungSang/warvis-findEvilW.A.R.V.I.S. — Forensic IR agent (Go orchestrator + Python MCP + Gemma 4). SANS FIND EVIL hackathon entry by WoopsFactory.
RELATED Other topics · full topics ranking →
#claude-code
1,555#ai-agents
1,156#llm
1,066#claude
936#python
802#ai
737#developer-tools
723#mcp
719#codex
517Aggregated by case-insensitive match against topics_json of each repo's latest content snapshot. methodology