MISP (core software) - Open Source Threat Intelligence and Sharing Platform
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
Sysmon configuration file template with default high-quality event tracing
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
#Awesome#✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
IntelOwl: manage your Threat Intelligence at scale
The Hunting ELK
#Awesome#A curated list of awesome YARA rules, tools, and people.
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, a...
Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, Threa...
Rapidly Search and Hunt through Windows Forensic Artefacts
Real-time HTTP Intrusion Detection
A repository of sysmon configuration modules
YARA signature and IOC database for my scanners and tools
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Interesting APT Report Collection And Some Special IOCs
Windows Events Attack Samples
Your Everyday Threat Intelligence