google/grr
GRR Rapid Response: remote live forensics for incident response observed · 2026-08-28
Health v2 · maintenance only
70/100
- Activity 82
- Release rhythm 37
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 145.0
- age_days: 4656
- days_rel: 261
- days_push: 113
- n_releases_24m: 3
Adoption not part of the score
5088 stars · 796 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
GRR Rapid Response is an incident response framework focused on remote live forensics. It consists of a Python agent installed on target systems and Python server infrastructure that manages and communicates with those clients.
Use cases
- remotely collect forensic artifacts from endpoints during an incident
- hunt across a fleet of machines for indicators of compromise
- investigate a suspected compromise on a remote host
- gather filesystem and system state evidence from live systems
- manage and query many endpoint agents from a central server
- perform large-scale triage during a security incident
When to choose
- you need remote live forensics across many endpoints
- you run a DFIR team and want an open-source agent/server framework
- you want to collect forensic data from systems without taking them offline
When to avoid
- you only need local disk forensics on offline images
- you want a lightweight EDR with real-time prevention rather than forensic collection
- you cannot deploy agents to target machines
Facets
framework · maturity active
security monitoring developer-tools security developer-tools python windows cross-platform self-hosted incident-response forensics remote-live-forensics dfir endpoint-agent automation linux macos
1 source
- readme: https://github.com/google/grr · fetched 2026-08-28 · 4b19f208b2e7
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| google/grr | main | 70 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem