mthcht

Elite
@mthcht

Threat Hunting - DFIR - Detection Engineering

awesome-lists. Awesome Security lists for SOC/CERT/CTI

1.8k

ThreatHunting-Keywords. Awesome list of keywords and artifacts for Threat Hunting sessions

670

Purpleteam. Purpleteam scripts simulation & Detection - trigger events for SOC detections

206

ThreatIntel-Reports. Raw data from Threat Intelligence Reports with automatic reports collection and keyword search across thousands of reports

169

ThreatHunting-Keywords-yara-rules. yara detection rules for hunting with the threathunting-keywords project

166

ThreatHunting-Keywords-sigma-rules. Sigma detection rules for hunting with the threathunting-keywords project

60

lookup-editor_scripts. scripts using splunk application lookup-editor endpoint. Download, upload and update splunk lookups content

32

mthcht.

8

OpenProject. A practical resource on using open-source tools for Incident Response. This repo shares workflows, tool setups, and steps for responding quickly to security incidents.

6

deepdarkCTI. Collection of Cyber Threat Intelligence sources from the deep and dark web

6

iocs. Indicators from Unit 42 Public Reports

5

Splunk4DFIR. harness the power of Splunk for your investigations

5

ransomware_notes. An Archive of Ransomware Notes Past and Present Collected by Zscaler ThreatLabz

5

Splunk-Search-Recipes. A curated collection of Splunk searches across multiple categories, designed to assist in data analysis, monitoring, and troubleshooting

4

Ultimate-RAT-Collection. For educational purposes only, exhaustive samples of 450+ classic/modern trojan builders including screenshots.

4

Hunting-Queries-Detection-Rules. KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

4

awesome-yara. A curated list of awesome YARA rules, tools, and people.

4

PayloadsAllTheThings. A list of useful payloads and bypass for Web Application Security and Pentest/CTF

3

Ransomware-Tool-Matrix. A resource containing all the tools each ransomware gangs uses

3

awesome-tunneling. List of ngrok/Cloudflare Tunnel alternatives and other tunneling software and services. Focus on self-hosting.

3

dns-blocklists. DNS-Blocklists: For a better internet - keep the internet clean!

3

security_content. Splunk Security Content

3

dnstwist. Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

3

MAL-CL. MAL-CL (Malicious Command-Line)

3

uac. UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.

3

Detection-Validation. Detection rule validation

3

ClatScope. ClatScope Info Tool – The best and most versatile OSINT utility for retrieving geolocation, DNS, WHOIS, phone, email, data breach information and much more (70+ features). Perfect for investigators, pentesters, or anyone looking for an effective reconnaissance / OSINT tool.

2

maltrail. Malicious traffic detection system

2

Remote-administration-tools-archive. Here are +200 different rats some with source code

2

cti. Cyber Threat Intelligence Repository expressed in STIX 2.0

2

EDR-Telemetry. This project aims to compare and evaluate the telemetry of various EDR products.

2

EventLogs-Samples. Raw events logs from simulated or real attacks

2

AutonomousThreatSweeper. Threat Hunting queries for various attacks

2

ADTimeline. Timeline of Active Directory changes with replication metadata

2

RdpCacheStitcher. RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

2

rpcfirewall. C++

2

ThreatHunter-Playbook. A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

2

Open-Source-Threat-Intel-Feeds. This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.

2

dyn-dns-list. This repository contains a comprehensive list of over 30k dynamic DNS domains as of 2024. The list is provided for informational purposes only and can be used for a variety of purposes, including blocking malicious domains, filtering content, and enhancing privacy and security.

2

lolcerts. A repository of code signing certificates known to have been leaked or stolen, then abused by threat actors

2

PSBits. Simple (relatively) things allowing you to dig a bit deeper than usual.

2

Malware-Knowledge-Graph. Create malware knowledge graphs from analysis reports

2

fapro. Fake Protocol Server

2

laurel. Transform Linux Audit logs for SIEM usage

2

dfir-orc. Forensics artefact collection tool for systems running Microsoft Windows

2

ACCD. Active C&C Detector

2

chainsaw. Rapidly Search and Hunt through Windows Forensic Artefacts

2

DefenderYara. Extracted Yara rules from Windows Defender mpavbase and mpasbase

1

C2-Tracker. Live Feed of C2 servers, tools, and botnets

1

KapeFiles2DFIR-orc-config. Convert Kape Files to DFIR-ORC configurations

1

LOLRMM. LotL RMM

1

jarm. Python

1

ThreatIntelligenceCorpus.

1

MITRE-Mappings. A public repository of MITRE ATT&ACK TTP mappings by BushidoUK for OSINT reports that lack a section breaking down the TTPs.

1

WELA. WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)

1

InsightEngineering.

1

bmc-tools. RDP Bitmap Cache parser

1
57
Apply