ThreatHunting

Domain scanner

Tools and rules for detecting malicious domain calls in endpoint malware

Tools for hunting for threats.

GitHub

568 stars
50 watching
55 forks
Language: YARA
last commit: about 1 month ago
nexthinkthreat-hunting

Related projects:

Repository Description Stars
threatexpress/domainhunter Tools for identifying suitable domains for malicious activities 1,543
a3sal0n/cyberthreathunting A collection of tools and resources for threat hunters to identify and respond to cyber threats. 855
sbousseaden/slides Collection of resources and concepts for threat hunting and detection engineering. 372
threathuntingproject/threathunting An informational repository providing resources and knowledge for detecting adversaries in IT environments. 1,722
sapphirex00/threat-hunting A collection of threat intelligence resources and tools for analyzing APT malware 255
ninoseki/mihari An aggregator tool for querying multiple services to gather threat intelligence data. 863
infocyte/pshunt A Powershell Threat Hunting Module designed to scan and survey remote endpoints for indicators of compromise or comprehensive system information. 279
matamorphosis/scrummage A platform for searching and analyzing publicly available online data to detect potential security threats 512
miladaslaner/threathunt A PowerShell repository to simulate and train threat hunting skills without malicious files. 134
kevthehermit/pastehunter Automates scanning of publicly hosted pasted data against Yara rules to identify potential security or research threats. 1,065
aboutsecurity/rastrea2r A tool for hunting and tracking Internet of Things (IoT) security threats by collecting and analyzing indicators of compromise (IOCs) 116
mhaggis/hunt-detect-prevent A collection of resources and tools for detecting and preventing malicious activity on Windows systems. 162
datadog/threatest Tools for testing and verifying threat detection rules 319
bloodhoundad/bloodhound-tools Tools and utilities to support the BloodHound threat hunting framework 377
inquest/threatingestor Extracts and aggregates threat intelligence from various sources 831