EventList

Hunting query generator

An automation tool that integrates Microsoft Security Baselines and MITRE ATT&CK to generate hunting queries for security operation centers.

EventList

GitHub

370 stars
33 watching
40 forks
Language: PowerShell
last commit: over 5 years ago

Related projects:

RepositoryDescriptionStars
bert-janp/hunting-queries-detection-rulesProvides KQL queries for hunting and detection in security logs1,292
kevthehermit/pastehunterAutomates scanning of publicly hosted pasted data against Yara rules to identify potential security or research threats.1,069
cert-polska/mqueryA web-based Yara query accelerator for malware analysis and digital forensics417
a3sal0n/cyberthreathuntingA collection of tools and resources for threat hunters to identify and respond to cyber threats.861
opencybersecurityalliance/kestrel-langA language and runtime framework for building reusable, composable threat hunting workflows using Python.302
kasperskylab/klaraHelps Threat Intelligence researchers hunt for new malware by efficiently scanning large collections of files with Yara rules698
mhaggis/hunt-detect-preventA collection of resources and tools for detecting and preventing malicious activity on Windows systems.162
ahmedkhlief/apt-hunterA tool to analyze Windows event logs for signs of APT attacks and malware activity.1,265
infocyte/pshuntA Powershell Threat Hunting Module designed to scan and survey remote endpoints for indicators of compromise or comprehensive system information.280
ninoseki/mihariAn aggregator tool for querying multiple services to gather threat intelligence data.870
sapphirex00/threat-huntingA collection of threat intelligence resources and tools for analyzing APT malware257
gossithedog/threathuntingTools and rules for detecting malicious domain calls in endpoint malware570
alienvault-otx/yabinGenerates Yara signatures for identifying malware code similarities158
west-wind/threat-hunting-with-splunkProvides Splunk queries to detect vulnerability exploitation attempts and subsequent compromise, including threat hunting for MITRE ATT&CK TTPs58
olafhartong/threathuntingA Splunk application designed to guide threat hunts by mapping investigations to the MITRE ATT&CK framework1,141