Awesome Lists

awesome-threat-detection

by 0x4D31

awesome listpushed about 2 years ago

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

AI summary

Threat detection toolkit

A curated collection of threat detection and hunting resources, tools, and frameworks for security professionals.

stars
3.9K
forks
667
watching
196
awesome lists
4
entries
304
View on GitHub0x4d31.github.io/awesome-threat-detection

Embed the badge

Show how many awesome lists link to your project. The count updates automatically.

Awesome Lists badge
Markdown
[![Awesome Lists Badge](https://awesome.facts.dev/shield/0x4D31/awesome-threat-detection/links.svg)](https://awesome.facts.dev/awesome/0x4D31/awesome-threat-detection)
HTML
<a href="https://awesome.facts.dev/awesome/0x4D31/awesome-threat-detection"><img src="https://awesome.facts.dev/shield/0x4D31/awesome-threat-detection/links.svg" alt="Awesome Lists Badge" /></a>
Image URL
https://awesome.facts.dev/shield/0x4D31/awesome-threat-detection/links.svg

What's in the list

304 links in 38 sections, with live GitHub stats.activeno commit in 2y

Tools

  • MITRE ATT&CK Navigator

    ( ) - The ATT&CK Navigator is designed to provide basic navigation and annotation of ATT&CK matrices, something that people are already doing today in tools like Excel

  • HELK

    A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities

  • DetectionLab

    Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices

  • Revoke-Obfuscation

    PowerShell Obfuscation Detection Framework

  • Invoke-ATTACKAPI

    A PowerShell script to interact with the MITRE ATT&CK Framework via its own API

  • Unfetter

    A reference implementation provides a framework for collecting events (process creation, network connections, Window Event Logs, etc.) from a client machine and performing CAR analytics to detect potential adversary activity

  • Flare

    An analytical framework for network traffic and behavioral analytics

  • RedHunt-OS

    A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment

  • Oriana

    Lateral movement and threat hunting tool for Windows environments built on Django comes Docker ready

  • Bro-Osquery

    Bro integration with osquery

  • Brosquery

    A module for osquery to load Bro logs into tables

  • DeepBlueCLI

    A PowerShell Module for Hunt Teaming via Windows Event Logs

  • Uncoder

    An online translator for SIEM saved searches, filters, queries, API requests, correlation and Sigma rules

  • CimSweep

    A suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows

  • Dispatch

    An open-source crisis management orchestration framework

  • EQL

    Event Query Language

Tools / EQL

  • EQLLib

    The Event Query Language Analytics Library (eqllib) is a library of event based analytics, written in EQL to detect adversary behaviors identified in MITRE ATT&CK™

Tools

  • BZAR

    (Bro/Zeek ATT&CK-based Analytics and Reporting) - A set of Zeek scripts to detect ATT&CK techniques

  • Security Onion

    An open-source Linux distribution for threat hunting, security monitoring, and log management. It includes ELK, Snort, Suricata, Zeek, Wazuh, Sguil, and many other security tools

  • Varna

    A quick & cheap AWS CloudTrail Monitoring with Event Query Language (EQL)

  • BinaryAlert

    Serverless, real-time & retroactive malware detection

  • hollows_hunter

    Scans all running processes, recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches)

  • ThreatHunting

    A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

  • Sentinel Attack

    A repository of Azure Sentinel alerts and hunting queries leveraging sysmon and the MITRE ATT&CK framework

  • Brim

    A desktop application to efficiently search large packet captures and Zeek logs

  • YARA

    The pattern matching swiss knife

  • Intel Owl

    An Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale

  • Capa

    An open-source tool to identify capabilities in executable files

  • Splunk Security Content

    Splunk-curated detection content that can easily be used accross many SIEMs (see Uncoder Rule Converter.)

  • Threat Bus

    Threat intelligence dissemination layer to connect security tools through a distributed publish/subscribe message broker

  • VAST

    A network telemetry engine for data-driven security investigations

  • zeek2es

    An open source tool to convert Zeek logs to Elastic/OpenSearch. You can also output pure JSON from Zeek's TSV logs!

  • LogSlash

    : A standard for reducing log volume without sacrificing analytical capability

  • SOC-Multitool

    : A powerful and user-friendly browser extension that streamlines investigations for security professionals

  • Zeek Analysis Tools (ZAT)

    : Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark

  • Synthetic Adversarial Log Objects (SALO)

    A framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event

Tools / Detection, Alerting and Automation Platforms

  • ElastAlert

    A framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch

  • StreamAlert

    A serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define

  • Matano

    : An open source security lake platform (SIEM alternative) for threat hunting, detection and response on AWS. Matano lets you write advanced detections as code (using python) to correlate and alert on threats in realtime

  • Shuffle

    : A general purpose security automation platform

  • Sublime

    : An open platform for detection, response, and threat hunting in email environments. Sublime lets you write advanced detections as code to alert and remediate threats like phishing in real-time

  • Substation

    A cloud native data pipeline and transformation toolkit for security teams

Tools / Endpoint Monitoring

  • osquery

    ( ) - SQL powered operating system instrumentation, monitoring, and analytics

  • Kolide Fleet

    A flexible control server for osquery fleets

  • Zeek Agent

    An endpoint monitoring agent that provides host activity to Zeek

  • Velociraptor

    Endpoint visibility and collection tool

  • Sysdig

    A tool for deep Linux system visibility, with native support for containers. Think about sysdig as strace + tcpdump + htop + iftop + lsof + ...awesome sauce

  • go-audit

    An alternative to the Linux auditd daemon

  • Sysmon

    A Windows system service and device driver that monitors and logs system activity to the Windows event log

  • OSSEC

    An open-source Host-based Intrusion Detection System (HIDS)

  • WAZUH

    An open-source security platform

  • sysmon-DFIR

    Sources, configuration and how to detect evil things utilizing Microsoft Sysmon

  • sysmon-config

    Sysmon configuration file template with default high-quality event tracing

  • sysmon-modular

    A repository of sysmon configuration modules. It also includes a of Sysmon configurations to MITRE ATT&CK techniques

  • osquery-configuration

    A repository for using osquery for incident detection and response

Tools / Network Monitoring

  • Zeek

    (formerly Bro) - A network security monitoring tool

  • ntopng

    A web-based network traffic monitoring tool

  • Suricata

    A network threat detection engine

  • Snort

    ( ) - A network intrusion detection tool

  • Joy

    A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring

  • Netcap

    A framework for secure and scalable network traffic analysis

  • Moloch

    A large scale and open source full packet capture and search tool

  • Stenographer

    A full-packet-capture tool

  • JA3

    A method for profiling SSL/TLS Clients and Servers

  • HASSH

    Profiling Method for SSH Clients and Servers

  • RDFP

    Zeek Remote desktop fingerprinting script based on (Fingerprint All The Things)

  • FATT

    A pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic

  • FingerprinTLS

    A TLS fingerprinting method

  • Mercury

    Network fingerprinting and packet metadata capture

  • Recog

    A framework for identifying products, services, operating systems, and hardware by matching fingerprints against data returned from various network probes

  • Hfinger

    Fingerprinting HTTP requests

  • JARM

    An active Transport Layer Security (TLS) server fingerprinting tool

Tools / Email Monitoring

Detection Rules

  • Sigma

    Generic Signature Format for SIEM Systems

  • MITRE CAR

    The Cyber Analytics Repository is a knowledge base of analytics developed by MITRE based on the Adversary Tactics, Techniques, and Common Knowledge (ATT&CK™) adversary model

  • Chronicle Detection Rules

    Collection of YARA-L 2.0 sample rules for the Chronicle Detection API

  • GCP Security Analytics

    Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud

  • ThreatHunter-Playbook

    A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient

  • Sublime Detection Rules

    Email attack detection, response, and hunting rules

Dataset

Resources

Resources / Frameworks

  • MITRE ATT&CK

    A curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target

  • Alerting and Detection Strategies Framework

    A framework for developing alerting and detection strategies

  • A Simple Hunting Maturity Model

    The Hunting Maturity Model describes five levels of organizational hunting capability, ranging from HMM0 (the least capability) to HMM4 (the most)

  • The Pyramic of Pain

    The relationship between the types of indicators you might use to detect an adversary's activities and how much pain it will cause them when you are able to deny those indicators to them

  • The PARIS Model

    A model for threat hunting

  • Cyber Kill Chain

    It is part of the Intelligence Driven Defense® model for identification and prevention of cyber intrusions activity. The model identifies what the adversaries must complete in order to achieve their objective

  • The DML Model

    The Detection Maturity Level (DML) model is a capability maturity model for referencing ones maturity in detecting cyber attacks

  • OSSEM

    (Open Source Security Events Metadata) - A community-led project that focuses on the documentation and standardization of security event logs from diverse data sources and operating systems

  • Open Cybersecurity Schema Framework (OCSF)

    A framework for creating schemas and it also delivers a cybersecurity event schema built with the framework ( )

  • MITRE Engage

    A framework for planning and discussing adversary engagement operations that empowers you to engage your adversaries and achieve your cybersecurity goals

  • MaGMa Use Case Defintion Model

    A business-centric approach for planning and defining threat detection use cases

Resources / Windows

Resources / Windows / JPCERT - Detecting Lateral Movement through Tracking Event Logs

Resources / Windows

Resources / Windows / Splunking the Endpoint: Threat Hunting with Sysmon

Resources / Windows

Resources / Windows / Chronicles of a Threat Hunter: Hunting for In-Memory Mimikatz with Sysmon and ELK

Resources / Windows

Resources / MacOS

Resources / Osquery

Resources / DNS

Resources / Fingerprinting

Resources / Fingerprinting / HASSH - a profiling method for SSH Clients and Servers

Resources / Fingerprinting

Resources / Data Science

Resources / Research Papers

Resources / Blogs

Podcasts

Newsletters

Videos

Trainings

Labs

  • DetectionLab

    Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices

  • Splunk Boss of the SOC

    Hands-on workshops and challenges to practice threat hunting using the BOTS and other datasets

  • HELK

    A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities

  • BlueTeam Lab

    A detection lab created with Terraform and Ansible in Azure

  • attack_range

    A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

Twitter

Threat Simulation Tools

  • MITRE CALDERA

    An automated adversary emulation system that performs post-compromise adversarial behavior within Windows Enterprise networks

  • APTSimulator

    A Windows Batch script that uses a set of tools and output files to make a system look as if it was compromised

  • Atomic Red Team

    Small and highly portable detection tests mapped to the Mitre ATT&CK Framework

  • Network Flight Simulator

    flightsim is a lightweight utility used to generate malicious network traffic and help security teams to evaluate security controls and network visibility

  • Metta

    A security preparedness tool to do adversarial simulation

  • Red Team Automation (RTA)

    RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK

  • SharpShooter

    Payload Generation Framework

  • CACTUSTORCH

    Payload Generation for Adversary Simulations

  • DumpsterFire

    A modular, menu-driven, cross-platform tool for building repeatable, time-delayed, distributed security events

  • Empire

    ( ) - A PowerShell and Python post-exploitation agent

  • PowerSploit

    A PowerShell Post-Exploitation Framework

  • RedHunt-OS

    A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment

  • Infection Monkey

    An open source Breach and Attack Simulation (BAS) tool that assesses the resiliency of private and public cloud environments to post-breach attacks and lateral movement

  • Splunk Attack Range

    A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk

Threat Simulation Resources

Threat Simulation Resources / SpecterOps Blog

Threat Simulation Resources

More related projects

Add a GitHub project

Missing a project or an awesome list? Paste its GitHub URL and we fetch it right away.