There are 139 repositories under threat-hunting topic.
Sysmon configuration file template with default high-quality event tracing
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
The Hunting ELK
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
A curated list of awesome YARA rules, tools, and people.
IntelOwl: manage your Threat Intelligence at scale
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, and case management. It also includes other tools such as Playbook, osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, InQuest and it is able to scan Android devices against VT.
Rapidly Search and Hunt through Windows Forensic Artefacts
A repository of sysmon configuration modules
YARA signature and IOC database for my scanners and tools
Interesting APT Report Collection And Some Special IOC
Windows Events Attack Samples
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Your Everyday Threat Intelligence
Utilities for Sysmon
Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍
A Suricata based IDS/IPS/NSM distro
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional free threat intelligence. Slava Ukraini. Glory to Ukraine.
🚀🚀 This is a 🎇🔥 REAL WORLD🔥 🎇 Malware Collection I have Compiled & analysed by researchers🔥 to understand more about Malware threats😈, analysis and mitigation🧐.
Repositório criado com intuito de reunir expressões regulares dentro do contexto Brasil
Watcher - Open Source Cybersecurity Threat Hunting Platform. Developed with Django & React JS.