awesome-lists. Awesome Security lists for SOC/CERT/CTI
1.8kThreatHunting-Keywords. Awesome list of keywords and artifacts for Threat Hunting sessions
670Purpleteam. Purpleteam scripts simulation & Detection - trigger events for SOC detections
206ThreatIntel-Reports. Raw data from Threat Intelligence Reports with automatic reports collection and keyword search across thousands of reports
169ThreatHunting-Keywords-yara-rules. yara detection rules for hunting with the threathunting-keywords project
166ThreatHunting-Keywords-sigma-rules. Sigma detection rules for hunting with the threathunting-keywords project
60lookup-editor_scripts. scripts using splunk application lookup-editor endpoint. Download, upload and update splunk lookups content
32mthcht.
8OpenProject. A practical resource on using open-source tools for Incident Response. This repo shares workflows, tool setups, and steps for responding quickly to security incidents.
6deepdarkCTI. Collection of Cyber Threat Intelligence sources from the deep and dark web
6iocs. Indicators from Unit 42 Public Reports
5Splunk4DFIR. harness the power of Splunk for your investigations
5ransomware_notes. An Archive of Ransomware Notes Past and Present Collected by Zscaler ThreatLabz
5Splunk-Search-Recipes. A curated collection of Splunk searches across multiple categories, designed to assist in data analysis, monitoring, and troubleshooting
4Ultimate-RAT-Collection. For educational purposes only, exhaustive samples of 450+ classic/modern trojan builders including screenshots.
4Hunting-Queries-Detection-Rules. KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
4awesome-yara. A curated list of awesome YARA rules, tools, and people.
4PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF
3Ransomware-Tool-Matrix. A resource containing all the tools each ransomware gangs uses
3awesome-tunneling. List of ngrok/Cloudflare Tunnel alternatives and other tunneling software and services. Focus on self-hosting.
3dns-blocklists. DNS-Blocklists: For a better internet - keep the internet clean!
3security_content. Splunk Security Content
3dnstwist. Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
3MAL-CL. MAL-CL (Malicious Command-Line)
3uac. UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
3Detection-Validation. Detection rule validation
3ClatScope. ClatScope Info Tool – The best and most versatile OSINT utility for retrieving geolocation, DNS, WHOIS, phone, email, data breach information and much more (70+ features). Perfect for investigators, pentesters, or anyone looking for an effective reconnaissance / OSINT tool.
2maltrail. Malicious traffic detection system
2Remote-administration-tools-archive. Here are +200 different rats some with source code
2cti. Cyber Threat Intelligence Repository expressed in STIX 2.0
2EDR-Telemetry. This project aims to compare and evaluate the telemetry of various EDR products.
2EventLogs-Samples. Raw events logs from simulated or real attacks
2AutonomousThreatSweeper. Threat Hunting queries for various attacks
2ADTimeline. Timeline of Active Directory changes with replication metadata
2RdpCacheStitcher. RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
2rpcfirewall. C++
2ThreatHunter-Playbook. A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
2Open-Source-Threat-Intel-Feeds. This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.
2dyn-dns-list. This repository contains a comprehensive list of over 30k dynamic DNS domains as of 2024. The list is provided for informational purposes only and can be used for a variety of purposes, including blocking malicious domains, filtering content, and enhancing privacy and security.
2lolcerts. A repository of code signing certificates known to have been leaked or stolen, then abused by threat actors
2PSBits. Simple (relatively) things allowing you to dig a bit deeper than usual.
2Malware-Knowledge-Graph. Create malware knowledge graphs from analysis reports
2fapro. Fake Protocol Server
2laurel. Transform Linux Audit logs for SIEM usage
2dfir-orc. Forensics artefact collection tool for systems running Microsoft Windows
2ACCD. Active C&C Detector
2chainsaw. Rapidly Search and Hunt through Windows Forensic Artefacts
2DefenderYara. Extracted Yara rules from Windows Defender mpavbase and mpasbase
1C2-Tracker. Live Feed of C2 servers, tools, and botnets
1KapeFiles2DFIR-orc-config. Convert Kape Files to DFIR-ORC configurations
1LOLRMM. LotL RMM
1jarm. Python
1ThreatIntelligenceCorpus.
1MITRE-Mappings. A public repository of MITRE ATT&ACK TTP mappings by BushidoUK for OSINT reports that lack a section breaking down the TTPs.
1WELA. WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)
1InsightEngineering.
1bmc-tools. RDP Bitmap Cache parser
1