Skip to main content
buildradar
Sign in
Topic · threat-hunting

threat-hunting

Tracked open-source repos tagged threat-hunting, sorted by stars.

Repos
66
Total stars
158,605
Avg. stars
2,403
Share
0.01%

Topics that frequently appear alongside threat-hunting on the same repo.

Recent risers

Repos created in the last 90 days, tagged threat-hunting.

No new repos tagged with this topic in the last 90 days.

  • 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

    32,040+0Star change over the last 7 days
  • Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.

    6,597+0Star change over the last 7 days
  • MISP@MISP

    MISP (core software) - Open Source Threat Intelligence and Sharing Platform

    6,497+0Star change over the last 7 days
  • dnstwist@elceef

    Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

    5,733+0Star change over the last 7 days
  • sysmon-config@SwiftOnSecurity

    Sysmon configuration file template with default high-quality event tracing

    5,635+0Star change over the last 7 days
  • securityonion@Security-Onion-Solutions

    Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

    4,862+0Star change over the last 7 days
  • ✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

    4,717+0Star change over the last 7 days
  • IntelOwl@intelowlproject

    IntelOwl: manage your Threat Intelligence at scale

    4,694+0Star change over the last 7 days
  • A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

    4,652+0Star change over the last 7 days
  • awesome-yara@pedramamini

    A curated list of awesome YARA rules, tools, and people.

    4,268+0Star change over the last 7 days
  • malwoverview@alexandreborges

    Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.

    4,079+0Star change over the last 7 days
  • HELK@Cyb3rWard0g

    The Hunting ELK

    3,931+0Star change over the last 7 days
  • chainsaw@WithSecureLabs

    Rapidly Search and Hunt through Windows Forensic Artefacts

    3,654+0Star change over the last 7 days
  • hayabusa@Yamato-Security

    Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

    3,333+0Star change over the last 7 days
  • sysmon-modular@olafhartong

    A repository of sysmon configuration modules

    3,124+0Star change over the last 7 days
  • APT_REPORT@blackorbird

    Interesting APT Report Collection And Some Special IOCs

    3,085+0Star change over the last 7 days
  • signature-base@Neo23x0

    YARA signature and IOC database for my scanners and tools

    3,018+0Star change over the last 7 days
  • detection-rules@elastic
    2,698+0Star change over the last 7 days
  • osint-brazuca@osintbrazuca

    Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.

    2,698+0Star change over the last 7 days
  • fibratus@rabbitstack

    Security sensor for realtime threat detection and protection

    2,536+0Star change over the last 7 days
  • yeti@yeti-platform

    Your Everyday Threat Intelligence

    2,022+0Star change over the last 7 days
  • awesome-lists@mthcht

    Awesome Security lists for SOC/CERT/CTI

    1,896+0Star change over the last 7 days
  • A curated knowledge base to build, run and mature a SOC (including CSIRT).

    1,809+0Star change over the last 7 days
  • KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

    1,737+0Star change over the last 7 days
  • investigations@AmnestyTech

    Indicators of Compromise from Amnesty International's cyber investigations

    1,698+0Star change over the last 7 days
  • matano@matanolabs

    Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

    1,694+0Star change over the last 7 days
  • SysmonTools@nshalabi

    Utilities for Sysmon

    1,662+0Star change over the last 7 days
  • Clear-NDR-ISO@StamusNetworks

    A Suricata based NDR distribution

    1,593+0Star change over the last 7 days
  • A resource containing all the tools each ransomware gangs uses

    1,435+0Star change over the last 7 days
  • APT-Hunter@ahmedkhlief

    APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

    1,418+0Star change over the last 7 days
← Back to topics