Ross ROSS = Recommend OSS · open-source software intelligence for agents

google/grr

GRR Rapid Response: remote live forensics for incident response observed · 2026-08-28

github.com/google/grr · homepage · Python · Apache-2.0 (permissive) observed · 2026-08-28

Health v2 · maintenance only

70/100

  • Activity 82
  • Release rhythm 37
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 145.0
  • age_days: 4656
  • days_rel: 261
  • days_push: 113
  • n_releases_24m: 3

Full methodology

Adoption not part of the score

5088 stars · 796 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

GRR Rapid Response is an incident response framework focused on remote live forensics. It consists of a Python agent installed on target systems and Python server infrastructure that manages and communicates with those clients.

Use cases

  • remotely collect forensic artifacts from endpoints during an incident
  • hunt across a fleet of machines for indicators of compromise
  • investigate a suspected compromise on a remote host
  • gather filesystem and system state evidence from live systems
  • manage and query many endpoint agents from a central server
  • perform large-scale triage during a security incident

When to choose

  • you need remote live forensics across many endpoints
  • you run a DFIR team and want an open-source agent/server framework
  • you want to collect forensic data from systems without taking them offline

When to avoid

  • you only need local disk forensics on offline images
  • you want a lightweight EDR with real-time prevention rather than forensic collection
  • you cannot deploy agents to target machines

Facets

framework · maturity active

security monitoring developer-tools security developer-tools python windows cross-platform self-hosted incident-response forensics remote-live-forensics dfir endpoint-agent automation linux macos

1 source

Member repositories

RepositoryRoleHealth v2
google/grrmain70

For agents

markdown · JSON · MCP: product_card(name="google/grr")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem