ThreatHunting

Domain scanner

Tools and rules for detecting malicious domain calls in endpoint malware

Tools for hunting for threats.

GitHub

570 stars
50 watching
55 forks
Language: YARA
last commit: almost 2 years ago
nexthinkthreat-hunting

Related projects:

RepositoryDescriptionStars
threatexpress/domainhunterTools for identifying suitable domains for malicious activities1,554
a3sal0n/cyberthreathuntingA collection of tools and resources for threat hunters to identify and respond to cyber threats.861
sbousseaden/slidesCollection of resources and concepts for threat hunting and detection engineering.372
threathuntingproject/threathuntingAn informational repository providing resources and knowledge for detecting adversaries in IT environments.1,726
sapphirex00/threat-huntingA collection of threat intelligence resources and tools for analyzing APT malware257
ninoseki/mihariAn aggregator tool for querying multiple services to gather threat intelligence data.870
infocyte/pshuntA Powershell Threat Hunting Module designed to scan and survey remote endpoints for indicators of compromise or comprehensive system information.280
matamorphosis/scrummageA platform for searching and analyzing publicly available online data to detect potential security threats515
miladaslaner/threathuntA PowerShell repository to simulate and train threat hunting skills without malicious files.134
kevthehermit/pastehunterAutomates scanning of publicly hosted pasted data against Yara rules to identify potential security or research threats.1,069
aboutsecurity/rastrea2rA tool for hunting and tracking Internet of Things (IoT) security threats by collecting and analyzing indicators of compromise (IOCs)116
mhaggis/hunt-detect-preventA collection of resources and tools for detecting and preventing malicious activity on Windows systems.162
datadog/threatestTools for testing and verifying threat detection rules322
bloodhoundad/bloodhound-toolsTools and utilities to support the BloodHound threat hunting framework380
inquest/threatingestorExtracts and aggregates threat intelligence from various sources836