All Categories → Security → threat-hunting

Top 115 threat-hunting open source projects

Detectionlabelk
DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.
Sysmon Config
Sysmon configuration file template with default high-quality event tracing
Attackdatamap
A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework
Dnstwist
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
Threatpinchlookup
Documentation and Sharing Repository for ThreatPinch Lookup Chrome & Firefox Extension
Stalkphish
StalkPhish - The Phishing kits stalker, harvesting phishing kits for investigations.
file watchtower
Lightweight File Integrity Monitoring Tool
pybinaryedge
Python 3 Wrapper for the BinaryEdge API https://www.binaryedge.io/
irma
enpoint detection / live analysis & sandbox host / signatures quality test
Memoirs-of-a-Threat-Hunter
My personal experience in Threat Hunting and knowledge gained so far.
OSINT-Brazuca
Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.
IronNetTR
Threat research and reporting from IronNet's Threat Research Teams
fastfinder
Incident Response - Fast suspicious file finder
Threat-Hunting-and-Detection
Repository for threat hunting and detection queries, tools, etc.
detection-rules
Threat Detection & Anomaly Detection rules for popular open-source components
BLUELAY
Searches online paste sites for certain search terms which can indicate a possible data breach.
S2AN
S2AN - Mapper of Sigma/Suricata Rules/Signatures ➡️ MITRE ATT&CK Navigator
Threathunting-book
Threat hunting Web Windows AD linux ATT&CK TTPs
kestrel-lang
Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.
hassh-utils
hassh-utils: Nmap NSE Script and Docker image for HASSH - the SSH client/server fingerprinting method (https://github.com/salesforce/hassh)
sqhunter
A simple threat hunting tool based on osquery, Salt Open and Cymon API
YaraHunts
Random hunting ordiented yara rules
ETWNetMonv3
ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
PowerGRR
PowerGRR is an API client library in PowerShell working on Windows, Linux and macOS for GRR automation and scripting.
SIGMA-detection-rules
Set of SIGMA rules (>250) mapped to MITRE Att@k tactic and techniques
SSHapendoes
Capture passwords of login attempts on non-existent and disabled accounts.
malware-persistence
Collection of malware persistence and hunting information. Be a persistent persistence hunter!
ps-srum-hunting
PowerShell Script to facilitate the processing of SRUM data for on-the-fly forensics and if needed threat hunting
thremulation-station
Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.
SysmonResources
Consolidation of various resources related to Microsoft Sysmon & sample data/log
DomainCAT
Domain Connectivity Analysis Tools to analyze aggregate connectivity patterns across a set of domains during security investigations
TA-Sysmon-deploy
Deploy and maintain Symon through the Splunk Deployment Sever
Owlyshield
Owlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact))..
Judge-Jury-and-Executable
A file system forensics analysis scanner and threat hunting tool. Scans file systems at the MFT and OS level and stores data in SQL, SQLite or CSV. Threats and data can be probed harnessing the power and syntax of SQL.
mail to misp
Connect your mail client/infrastructure to MISP in order to create events based on the information contained within mails.
evtx-hunter
evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.
61-115 of 115 threat-hunting projects