ThreatHunter-Playbook

Threat Hunter

A community-driven project providing shared detection logic and resources for threat hunting

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

GitHub

4k stars
373 watching
812 forks
Language: Python
last commit: over 2 years ago
Linked from 4 awesome lists

dfirhunterhuntinghunting-campaignshypothesismitremitre-attack-dbsysmonthreat-hunting

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
threathuntingproject/threathuntingAn informational repository providing resources and knowledge for detecting adversaries in IT environments.1,726
a3sal0n/cyberthreathuntingA collection of tools and resources for threat hunters to identify and respond to cyber threats.861
matamorphosis/scrummageA platform for searching and analyzing publicly available online data to detect potential security threats515
ninoseki/mihariAn aggregator tool for querying multiple services to gather threat intelligence data.870
miladaslaner/threathuntA PowerShell repository to simulate and train threat hunting skills without malicious files.134
opencybersecurityalliance/kestrel-langA language and runtime framework for building reusable, composable threat hunting workflows using Python.302
olafhartong/threathuntingA Splunk application designed to guide threat hunts by mapping investigations to the MITRE ATT&CK framework1,141
inquest/threatingestorExtracts and aggregates threat intelligence from various sources836
sbousseaden/slidesCollection of resources and concepts for threat hunting and detection engineering.372
otrf/security-datasetsProvides a repository of security event datasets to support threat research and analysis1,612
gossithedog/threathuntingTools and rules for detecting malicious domain calls in endpoint malware570
aboutsecurity/rastrea2rA tool for hunting and tracking Internet of Things (IoT) security threats by collecting and analyzing indicators of compromise (IOCs)116
kunai-project/kunaiAn eBPF-based tool for comprehensive Linux event monitoring and analysis403
sk4la/plastA modular threat-hunting tool framework for detecting indicators of compromise in incident-response operations.17
phantomcyber/playbooksCommunity-developed playbooks and custom functions for Splunk SOAR threat hunting and incident response478