threat-hunting
Tracked open-source repos tagged threat-hunting, sorted by stars.
- #31
Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.
★ 1,380+0Star change over the last 7 days - #32★ 1,336+0Star change over the last 7 days
- #33
🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍
★ 1,320+0Star change over the last 7 days - #34
A curated list of annual cyber security reports
★ 1,196+0Star change over the last 7 days - #35
🚀🚀 This is a 🎇🔥 REAL WORLD🔥 🎇 Malware Collection I have Compiled & analysed by researchers🔥 to understand more about Malware threats😈, analysis and mitigation🧐.
★ 1,183+0Star change over the last 7 days - #36★ 1,086+1Star change over the last 7 days
- #37
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
★ 1,078+0Star change over the last 7 days - #38
Repositório criado com intuito de reunir expressões regulares dentro do contexto Brasil
★ 1,012+6Star change over the last 7 days - #39
openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.
★ 985+3Star change over the last 7 days - #40
This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.
★ 945+6Star change over the last 7 days - #41★ 942+0Star change over the last 7 days
- #42
Open source platform for cyber security analysts with many features for threat intelligence and detection engineering.
★ 941+4Star change over the last 7 days - #43
Extract and aggregate threat intelligence.
★ 927-1Star change over the last 7 days - #44
A collection of resources for Threat Hunters
★ 918+1Star change over the last 7 days - #45
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
★ 826+2Star change over the last 7 days - #46
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
★ 796+1Star change over the last 7 days - #47
Automatically created C2 Feeds
★ 741-1Star change over the last 7 days - #48★ 730+0Star change over the last 7 days
- #49★ 728+0Star change over the last 7 days
- #50★ 710+4Star change over the last 7 days
- #51
A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.
★ 686+2Star change over the last 7 days - #52
Scirius is a web application for Suricata ruleset management and threat hunting.
★ 683+2Star change over the last 7 days - #53
Awesome list of keywords and artifacts for Threat Hunting sessions
★ 673+0Star change over the last 7 days - #54
常见的攻击行为监测特征及方法,涵盖端点和流量,未包含PowerShell和Sysmon。预祝运营生活愉快!
★ 653+0Star change over the last 7 days - #55
This repo is about Active Directory Advanced Threat Hunting
★ 653+0Star change over the last 7 days - #56
Production-ready detection & response queries for osquery
★ 643+0Star change over the last 7 days - #57
Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.
★ 642+1Star change over the last 7 days - #58
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
★ 639+6Star change over the last 7 days - #59
Clusters and elements to attach to MISP events or attributes (like threat actors)
★ 638-1Star change over the last 7 days - #60
PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform
★ 638+0Star change over the last 7 days