There are 8 repositories under threathunting topic.
IntelOwl: manage your Threat Intelligence at scale
Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, InQuest and it is able to scan Android devices against VT.
Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysis and hunting designed for intel and malware analysts as well as threat hunters to get up and running quickly.
Actionable analytics designed to combat threats
A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365
Microsoft Defender XDR - Resource Hub
Awesome list of keywords and artifacts for Threat Hunting sessions
Detecting ATT&CK techniques & tactics for Linux
Purpleteam scripts simulation & Detection - trigger events for SOC detections
This little tool is to calculate a MurmurHash value of a favicon to hunt phishing websites on the Shodan platform.
An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.
Collection of Dashboards for Threat Hunting and more!
Sigma detection rules for hunting with the threathunting-keywords project
Library of threat hunts to get any user started!
Volatility MindMap & Cheat Sheet
Tiny proof-of-concept PowerShell script to do threat hunting using ChatGPT (text-davinci-003)
Detect leaks in security event logs.
This is a simple Python script that connects to a MISP instance and retrieves attributes of specific types (such as IP addresses, URLs, and hashes). The retrieved attributes are then written to separate files.
Kit de herramientas para atender un incidente de Ciberseguridad y elementos claves para poder gestionar y analizar artefactos basados en una intrusión informática.
Project to Support The Hunter's Framework (THF)
🏴☠️ BST is an ever-evolving collection of 🛠 tools to help in security and administration day to day tasks 😉
Lightweight Endpoint Detection & Response (EDR) Framework
Pull your DS rules and build a ATT&CK matrix
A powershell tool that automate the remote forensic evidence adquisitions (triage) from Remote windows machines, using KAPE tool.
Short deep dive into Threat Hunting on AWS
Another Threat Hunting knowledge base :) based on MITRE ATT&CK Matrix
An updated fork of @3lp4tr0n's BeaconHunter. Detect and respond to Cobalt Strike beacons using ETW
Phishing Hunging Operations (PHOps) 🚀