awesome-threat-detection
by 0x4D31
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
AI summary
Threat detection toolkit
A curated collection of threat detection and hunting resources, tools, and frameworks for security professionals.
- stars
- 3.9K
- forks
- 667
- watching
- 196
- awesome lists
- 4
- entries
- 304
What's in the list
304 links in 38 sections, with live GitHub stats.activeno commit in 2y
Tools
- MITRE ATT&CK Navigator
( ) - The ATT&CK Navigator is designed to provide basic navigation and annotation of ATT&CK matrices, something that people are already doing today in tools like Excel
HELK
A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities
DetectionLab
Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices
Revoke-Obfuscation
PowerShell Obfuscation Detection Framework
Invoke-ATTACKAPI
A PowerShell script to interact with the MITRE ATT&CK Framework via its own API
Unfetter
A reference implementation provides a framework for collecting events (process creation, network connections, Window Event Logs, etc.) from a client machine and performing CAR analytics to detect potential adversary activity
Flare
An analytical framework for network traffic and behavioral analytics
RedHunt-OS
A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment
Oriana
Lateral movement and threat hunting tool for Windows environments built on Django comes Docker ready
Bro-Osquery
Bro integration with osquery
Brosquery
A module for osquery to load Bro logs into tables
DeepBlueCLI
A PowerShell Module for Hunt Teaming via Windows Event Logs
- Uncoder
An online translator for SIEM saved searches, filters, queries, API requests, correlation and Sigma rules
CimSweep
A suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows
Dispatch
An open-source crisis management orchestration framework
EQL
Event Query Language
Tools / EQL
EQLLib
The Event Query Language Analytics Library (eqllib) is a library of event based analytics, written in EQL to detect adversary behaviors identified in MITRE ATT&CK™
Tools
BZAR
(Bro/Zeek ATT&CK-based Analytics and Reporting) - A set of Zeek scripts to detect ATT&CK techniques
Security Onion
An open-source Linux distribution for threat hunting, security monitoring, and log management. It includes ELK, Snort, Suricata, Zeek, Wazuh, Sguil, and many other security tools
Varna
A quick & cheap AWS CloudTrail Monitoring with Event Query Language (EQL)
BinaryAlert
Serverless, real-time & retroactive malware detection
hollows_hunter
Scans all running processes, recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches)
ThreatHunting
A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
Sentinel Attack
A repository of Azure Sentinel alerts and hunting queries leveraging sysmon and the MITRE ATT&CK framework
Brim
A desktop application to efficiently search large packet captures and Zeek logs
YARA
The pattern matching swiss knife
Intel Owl
An Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale
Capa
An open-source tool to identify capabilities in executable files
Splunk Security Content
Splunk-curated detection content that can easily be used accross many SIEMs (see Uncoder Rule Converter.)
Threat Bus
Threat intelligence dissemination layer to connect security tools through a distributed publish/subscribe message broker
VAST
A network telemetry engine for data-driven security investigations
zeek2es
An open source tool to convert Zeek logs to Elastic/OpenSearch. You can also output pure JSON from Zeek's TSV logs!
LogSlash
: A standard for reducing log volume without sacrificing analytical capability
SOC-Multitool
: A powerful and user-friendly browser extension that streamlines investigations for security professionals
Zeek Analysis Tools (ZAT)
: Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark
Synthetic Adversarial Log Objects (SALO)
A framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event
Tools / Detection, Alerting and Automation Platforms
ElastAlert
A framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch
StreamAlert
A serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define
Matano
: An open source security lake platform (SIEM alternative) for threat hunting, detection and response on AWS. Matano lets you write advanced detections as code (using python) to correlate and alert on threats in realtime
Shuffle
: A general purpose security automation platform
Sublime
: An open platform for detection, response, and threat hunting in email environments. Sublime lets you write advanced detections as code to alert and remediate threats like phishing in real-time
Substation
A cloud native data pipeline and transformation toolkit for security teams
Tools / Endpoint Monitoring
- osquery
( ) - SQL powered operating system instrumentation, monitoring, and analytics
Kolide Fleet
A flexible control server for osquery fleets
Zeek Agent
An endpoint monitoring agent that provides host activity to Zeek
Velociraptor
Endpoint visibility and collection tool
Sysdig
A tool for deep Linux system visibility, with native support for containers. Think about sysdig as strace + tcpdump + htop + iftop + lsof + ...awesome sauce
go-audit
An alternative to the Linux auditd daemon
- Sysmon
A Windows system service and device driver that monitors and logs system activity to the Windows event log
OSSEC
An open-source Host-based Intrusion Detection System (HIDS)
WAZUH
An open-source security platform
sysmon-DFIR
Sources, configuration and how to detect evil things utilizing Microsoft Sysmon
sysmon-config
Sysmon configuration file template with default high-quality event tracing
sysmon-modular
A repository of sysmon configuration modules. It also includes a of Sysmon configurations to MITRE ATT&CK techniques
osquery-configuration
A repository for using osquery for incident detection and response
Tools / Network Monitoring
Zeek
(formerly Bro) - A network security monitoring tool
ntopng
A web-based network traffic monitoring tool
- Suricata
A network threat detection engine
- Snort
( ) - A network intrusion detection tool
Joy
A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring
Netcap
A framework for secure and scalable network traffic analysis
Moloch
A large scale and open source full packet capture and search tool
Stenographer
A full-packet-capture tool
JA3
A method for profiling SSL/TLS Clients and Servers
HASSH
Profiling Method for SSH Clients and Servers
RDFP
Zeek Remote desktop fingerprinting script based on (Fingerprint All The Things)
FATT
A pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic
FingerprinTLS
A TLS fingerprinting method
Mercury
Network fingerprinting and packet metadata capture
Recog
A framework for identifying products, services, operating systems, and hardware by matching fingerprints against data returned from various network probes
Hfinger
Fingerprinting HTTP requests
JARM
An active Transport Layer Security (TLS) server fingerprinting tool
Tools / Email Monitoring
Sublime Platform
An email threat detection engine
Detection Rules
Sigma
Generic Signature Format for SIEM Systems
- MITRE CAR
The Cyber Analytics Repository is a knowledge base of analytics developed by MITRE based on the Adversary Tactics, Techniques, and Common Knowledge (ATT&CK™) adversary model
Chronicle Detection Rules
Collection of YARA-L 2.0 sample rules for the Chronicle Detection API
GCP Security Analytics
Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud
ThreatHunter-Playbook
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient
Sublime Detection Rules
Email attack detection, response, and hunting rules
Dataset
Mordor
Pre-recorded security events generated by simulated adversarial techniques in the form of JavaScript Object Notation (JSON) files. The data is categorized by platforms, adversary groups, tactics and techniques defined by the Mitre ATT&CK Framework
- SecRepo.com
( ) - Samples of security related data
EMBER
( ) - The EMBER dataset is a collection of features from PE files that serve as a benchmark dataset for researchers
theZoo
A repository of LIVE malwares
- CIC Datasets
Canadian Institute for Cybersecurity datasets
- Netresec's PCAP repo list
A list of public packet capture repositories, which are freely available on the Internet
PCAP-ATTACK
A repo of PCAP samples for different ATT&CK techniques
EVTX-ATTACK-SAMPLES
A repo of Windows event samples (EVTX) associated with ATT&CK techniques ( )
attack_data
A repository of curated datasets from various attacks
Resources
- Huntpedia
Your Threat Hunting Knowledge Compendium
- Hunt Evil
Your Practical Guide to Threat Hunting
- The Hunter's Handbook
Endgame's guide to adversary hunting
ThreatHunter-Playbook
A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns
The ThreatHunting Project
A great and threat hunting resources
CyberThreatHunting
A collection of resources for threat hunters
Hunt-Detect-Prevent
Lists of sources and utilities to hunt, detect and prevent evildoers
Deception-as-Detection
Deception based detection techniques mapped to the MITRE’s ATT&CK framework
- Slides
Hunting On The Cheap ( )
- Signal the ATT&CK: Part 1
Building a real-time threat detection capability with Tanium that focuses on documented adversarial techniques
- DFIR
SANS Summit Archives ( , ) - Threat hunting, Blue Team and DFIR summit slides
- Bro-Osquery
Large-Scale Host and Network Monitoring Using Open-Source Software
Malware Persistence
Collection of various information focused on malware persistence: detection (techniques), response, pitfalls and the log collection (tools)
Awesome YARA
A curated list of awesome YARA rules, tools, and resources
- Defining ATT&CK Data Sources
A two-part blog series that outlines a new methodology to extend ATT&CK’s current data sources
- DETT&CT: MAPPING YOUR BLUE TEAM TO MITRE ATT&CK™
A blog that describes how to align MITRE ATT&CK-based detection content with data sources
- Part 1,
Detection as Code in Splunk - A multipart series describing how detection as code can be successfully deployed in a Splunk environment
- Lessons Learned in Detection Engineering
A well experienced detection engineer describes in detail his observations, challenges, and recommendations for building an effective threat detection program
- Investigation Scenario
tweets by Chris Sanders
- Oh My Malware
A video series focused on malware execution and investigations using Elastic Security
Resources / Frameworks
- MITRE ATT&CK
A curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target
Alerting and Detection Strategies Framework
A framework for developing alerting and detection strategies
- A Simple Hunting Maturity Model
The Hunting Maturity Model describes five levels of organizational hunting capability, ranging from HMM0 (the least capability) to HMM4 (the most)
- The Pyramic of Pain
The relationship between the types of indicators you might use to detect an adversary's activities and how much pain it will cause them when you are able to deny those indicators to them
- The PARIS Model
A model for threat hunting
- Cyber Kill Chain
It is part of the Intelligence Driven Defense® model for identification and prevention of cyber intrusions activity. The model identifies what the adversaries must complete in order to achieve their objective
- The DML Model
The Detection Maturity Level (DML) model is a capability maturity model for referencing ones maturity in detecting cyber attacks
OSSEM
(Open Source Security Events Metadata) - A community-led project that focuses on the documentation and standardization of security event logs from diverse data sources and operating systems
Open Cybersecurity Schema Framework (OCSF)
A framework for creating schemas and it also delivers a cybersecurity event schema built with the framework ( )
- MITRE Engage
A framework for planning and discussing adversary engagement operations that empowers you to engage your adversaries and achieve your cybersecurity goals
- MaGMa Use Case Defintion Model
A business-centric approach for planning and defining threat detection use cases
Resources / Windows
Windows Hunting
A collection of Windows hunting queries
Resources / Windows / JPCERT - Detecting Lateral Movement through Tracking Event Logs
Resources / Windows
Resources / Windows / Splunking the Endpoint: Threat Hunting with Sysmon
Resources / Windows
Resources / Windows / Chronicles of a Threat Hunter: Hunting for In-Memory Mimikatz with Sysmon and ELK
Resources / Windows
- botconf 2016 Slides
Advanced Incident Detection and Threat Hunting using Sysmon (and Splunk) ( , )
- Paper
Revoke-Obfuscation: PowerShell Obfuscation Detection Using Science ( , )
Resources / MacOS
Resources / Osquery
- osquery for Security — Part 2
Advanced osquery functionality, File integrity monitoring, process auditing, and more
Resources / DNS
- DNS is NOT Boring
Using DNS to Expose and Thwart Attacks
- Actionable Detects
Blue Team Tactics
Resources / Fingerprinting
Resources / Fingerprinting / HASSH - a profiling method for SSH Clients and Servers
Resources / Fingerprinting
- JA3er
a DB of JA3 fingerprints
- TLS Fingerprints
collected from the University of Colorado Boulder campus network
Resources / Data Science
data_hacking
Examples of using IPython, Pandas, and Scikit Learn to get the most out of your security data
msticpy
A library for InfoSec investigation and hunting in Jupyter Notebooks
Resources / Research Papers
- Paper
A Comprehensive Approach to Intrusion Detection Alert Correlation ( , )
Resources / Blogs
Resources / Related Awesome Lists
Podcasts
- Cloud Security Podcast
Google by Anton Chuvakin and Timothy Peacock
- Detection: Challenging Paradigms
by SpecterOps
- Darknet Diaries
by Andy Greenberg - True stories from the dark side of the Internet
- Risky Business
by Patrick Gray
Newsletters
- Detection Engineering Weekly
by Zack 'techy' Allen
- This Week in 4n6
A weekly roundup of digital forensics and incident response news
Videos
- QueryCon 2018
An annual conference for the osquery open-source community ( )
Trainings
- Applied Network Defense
courses by Chris Sanders
- Security Blue Team
(BTL1 and BTL2 certificates)
- LetsDefend
Hands-On SOC Analyst Training
- TryHackMe
Hands-on cyber security training through real-world scenarios
- Investigating Windows Endpoints
13Cubed, by Richard Davis
- HackTheBox
While not directly related to threat detection, the website features training modules on general security and offensive topics that can be beneficial for junior SOC analysts
Labs
DetectionLab
Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices
- Splunk Boss of the SOC
Hands-on workshops and challenges to practice threat hunting using the BOTS and other datasets
HELK
A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities
BlueTeam Lab
A detection lab created with Terraform and Ansible in Azure
attack_range
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
- "Awesome Detection" Twitter List
Twitter accounts that tweet about threat detection, hunting and DFIR
Threat Simulation Tools
MITRE CALDERA
An automated adversary emulation system that performs post-compromise adversarial behavior within Windows Enterprise networks
APTSimulator
A Windows Batch script that uses a set of tools and output files to make a system look as if it was compromised
Atomic Red Team
Small and highly portable detection tests mapped to the Mitre ATT&CK Framework
Network Flight Simulator
flightsim is a lightweight utility used to generate malicious network traffic and help security teams to evaluate security controls and network visibility
Metta
A security preparedness tool to do adversarial simulation
Red Team Automation (RTA)
RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK
SharpShooter
Payload Generation Framework
CACTUSTORCH
Payload Generation for Adversary Simulations
DumpsterFire
A modular, menu-driven, cross-platform tool for building repeatable, time-delayed, distributed security events
Empire
( ) - A PowerShell and Python post-exploitation agent
PowerSploit
A PowerShell Post-Exploitation Framework
RedHunt-OS
A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment
Infection Monkey
An open source Breach and Attack Simulation (BAS) tool that assesses the resiliency of private and public cloud environments to post-breach attacks and lateral movement
Splunk Attack Range
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk
Threat Simulation Resources
Awesome Red Teaming
A list of awesome red teaming resources
Red-Team Infrastructure Wiki
Wiki to collect Red Team infrastructure hardening resources
Threat Simulation Resources / SpecterOps Blog
Threat Simulation Resources
- Advanced Threat Tactics
A free course on red team operations and adversary simulations
- Signal the ATT&CK: Part 1
Modelling APT32 in CALDERA
Red Teaming/Adversary Simulation Toolkit
A collection of open source and commercial tools that aid in red team operations
- C2 Matrix
( )
adversary_emulation_library
An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs
Nothing in this list matches your filter.
Featured in 4 awesome lists
Each link jumps to the spot where the list mentions awesome-threat-detection.
More related projects
withsecurelabs/leonidas535
netspi/esc283
yamato-security/enablewindowslogsettings571
mdecrevoisier/evtx-to-mitre-attack532
lprat/static_file_analysis49
datadog/stratus-red-team1.9K
yamato-security/hayabusa2.4K
geeksniper/active-directory-pentest156
hausec/adape-script1.1K
antoniococo/sharpyshell922
neo23x0/sysmon-config457