Linux systems continue to play a central role in modern infrastructures, and effective incident response depends on having reliable, well‑maintained tools close at hand. To support practitioners, students, and teams working in this space, we’ve published a new page on our website highlighting a curated selection of Linux IR tools that we regularly reference during investigations.
Rather than attempting to catalogue every script or utility available online, this collection focuses on tools that have demonstrated consistent value in real‑world DFIR workflows. Each entry includes a short description and a link to the official source, making it easy to evaluate whether a tool fits your environment or response process.
You can access the new resource here:
https://www.halkynconsulting.co.uk/security-resources/linux-incident-response-tools
Our goal is simple: provide a dependable starting point for responders who need trustworthy options for triage, evidence collection, and analysis across Linux systems. Whether you’re building a lab, refreshing your playbooks, or teaching incident response fundamentals, we hope this page helps streamline your work.
We’ll continue to update the list over time as tools evolve and new capabilities emerge. If you have suggestions or tools you believe should be included, we welcome recommendations from the wider community.