Skip to main content
buildradar
Sign in
Topic · threat-hunting

threat-hunting

Tracked open-source repos tagged threat-hunting, sorted by stars.

66 repos
  • Watcher@thalesgroup-cert

    Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.

    1,380+0Star change over the last 7 days
  • BLUESPAWN@ION28

    An Active Defense and EDR software to empower Blue Teams

    1,336+0Star change over the last 7 days
  • YaraHunter@deepfence

    🔍🔍 Malware scanner for cloud-native, as part of CI/CD and at Runtime 🔍🔍

    1,320+0Star change over the last 7 days
  • A curated list of annual cyber security reports

    1,196+0Star change over the last 7 days
  • Malware-Exhibit@alvin-tosh

    🚀🚀 This is a 🎇🔥 REAL WORLD🔥 🎇 Malware Collection I have Compiled & analysed by researchers🔥 to understand more about Malware threats😈, analysis and mitigation🧐.

    1,183+0Star change over the last 7 days
  • kunai@kunai-project

    Threat-hunting tool for Linux

    1,086+1Star change over the last 7 days
  • sentinel-attack@edoardogerosa

    Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK

    1,078+0Star change over the last 7 days
  • osint-brazuca-regex@osintbrazuca

    Repositório criado com intuito de reunir expressões regulares dentro do contexto Brasil

    1,012+6Star change over the last 7 days
  • opensquat@atenreiro

    openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.

    985+3Star change over the last 7 days
  • This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.

    945+6Star change over the last 7 days
  • mihari@ninoseki

    A query aggregator for OSINT based threat hunting

    942+0Star change over the last 7 days
  • osint_toolkit@dev-lu

    Open source platform for cyber security analysts with many features for threat intelligence and detection engineering.

    941+4Star change over the last 7 days
  • ThreatIngestor@pedramamini

    Extract and aggregate threat intelligence.

    927-1Star change over the last 7 days
  • CyberThreatHunting@A3sal0n

    A collection of resources for Threat Hunters

    918+1Star change over the last 7 days
  • Threat-Hunting-and-Detection@Cyb3r-Monk

    Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).

    826+2Star change over the last 7 days
  • A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

    796+1Star change over the last 7 days
  • C2IntelFeeds@drb-ra

    Automatically created C2 Feeds

    741-1Star change over the last 7 days
  • SIEM@TonyPhipps

    SIEM Tactics, Techiques, and Procedures

    730+0Star change over the last 7 days
  • klara@KasperskyLab

    Kaspersky's GReAT KLara

    728+0Star change over the last 7 days
  • Hawkeye@mir1ce

    Windows应急响应工具---Hawkeye(鹰眼)。集Windows日志分析,进程扫描,主机信息于一体的综合应急响应分析工具

    710+4Star change over the last 7 days
  • cyberbro@stanfrbd

    A simple application that extracts your IoCs from garbage input and checks their reputation using multiple CTI services.

    686+2Star change over the last 7 days
  • scirius@StamusNetworks

    Scirius is a web application for Suricata ruleset management and threat hunting.

    683+2Star change over the last 7 days
  • ThreatHunting-Keywords@mthcht

    Awesome list of keywords and artifacts for Threat Hunting sessions

    673+0Star change over the last 7 days
  • 常见的攻击行为监测特征及方法,涵盖端点和流量,未包含PowerShell和Sysmon。预祝运营生活愉快!

    653+0Star change over the last 7 days
  • This repo is about Active Directory Advanced Threat Hunting

    653+0Star change over the last 7 days
  • osquery-defense-kit@chainguard-dev

    Production-ready detection & response queries for osquery

    643+0Star change over the last 7 days
  • Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.

    642+1Star change over the last 7 days
  • rita@activecm

    Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

    639+6Star change over the last 7 days
  • misp-galaxy@MISP

    Clusters and elements to attach to MISP events or attributes (like threat actors)

    638-1Star change over the last 7 days
  • PatrowlManager@Patrowl

    PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform

    638+0Star change over the last 7 days
← Back to topics