threat-hunting
Tracked open-source repos tagged threat-hunting, sorted by stars.
Related topics
Topics that frequently appear alongside threat-hunting on the same repo.
Recent risers
Repos created in the last 90 days, tagged threat-hunting.
No new repos tagged with this topic in the last 90 days.
- #1
817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
★ 32,040+0Star change over the last 7 days - #2
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.
★ 6,597+0Star change over the last 7 days - #3★ 6,497+0Star change over the last 7 days
- #4
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
★ 5,733+0Star change over the last 7 days - #5
Sysmon configuration file template with default high-quality event tracing
★ 5,635+0Star change over the last 7 days - #6
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
★ 4,862+0Star change over the last 7 days - #7
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
★ 4,717+0Star change over the last 7 days - #8★ 4,694+0Star change over the last 7 days
- #9
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
★ 4,652+0Star change over the last 7 days - #10
A curated list of awesome YARA rules, tools, and people.
★ 4,268+0Star change over the last 7 days - #11
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
★ 4,079+0Star change over the last 7 days - #12★ 3,931+0Star change over the last 7 days
- #13★ 3,654+0Star change over the last 7 days
- #14
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
★ 3,333+0Star change over the last 7 days - #15
A repository of sysmon configuration modules
★ 3,124+0Star change over the last 7 days - #16
Interesting APT Report Collection And Some Special IOCs
★ 3,085+0Star change over the last 7 days - #17
YARA signature and IOC database for my scanners and tools
★ 3,018+0Star change over the last 7 days - #18★ 2,698+0Star change over the last 7 days
- #19
Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.
★ 2,698+0Star change over the last 7 days - #20★ 2,536+0Star change over the last 7 days
- #21★ 2,022+0Star change over the last 7 days
- #22
Awesome Security lists for SOC/CERT/CTI
★ 1,896+0Star change over the last 7 days - #23
A curated knowledge base to build, run and mature a SOC (including CSIRT).
★ 1,809+0Star change over the last 7 days - #24
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
★ 1,737+0Star change over the last 7 days - #25
Indicators of Compromise from Amnesty International's cyber investigations
★ 1,698+0Star change over the last 7 days - #26
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
★ 1,694+0Star change over the last 7 days - #27
Utilities for Sysmon
★ 1,662+0Star change over the last 7 days - #28
A Suricata based NDR distribution
★ 1,593+0Star change over the last 7 days - #29
A resource containing all the tools each ransomware gangs uses
★ 1,435+0Star change over the last 7 days - #30
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
★ 1,418+0Star change over the last 7 days