ThreatHunting

Threat Hunting App

A Splunk application designed to guide threat hunts by mapping investigations to the MITRE ATT&CK framework

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

GitHub

1k stars
63 watching
179 forks
last commit: about 3 years ago
Linked from 1 awesome list

dfirmitre-attacksplunkthreat-hunting

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
west-wind/threat-hunting-with-splunkProvides Splunk queries to detect vulnerability exploitation attempts and subsequent compromise, including threat hunting for MITRE ATT&CK TTPs58
inodee/threathunting-splProvides Splunk code and prototypes for building rules and queries to detect malicious activity268
sbousseaden/slidesCollection of resources and concepts for threat hunting and detection engineering.372
a3sal0n/cyberthreathuntingA collection of tools and resources for threat hunters to identify and respond to cyber threats.861
otrf/threathunter-playbookA community-driven project providing shared detection logic and resources for threat hunting4,049
threathuntingproject/threathuntingAn informational repository providing resources and knowledge for detecting adversaries in IT environments.1,726
ninoseki/mihariAn aggregator tool for querying multiple services to gather threat intelligence data.870
miladaslaner/threathuntA PowerShell repository to simulate and train threat hunting skills without malicious files.134
gossithedog/threathuntingTools and rules for detecting malicious domain calls in endpoint malware570
matamorphosis/scrummageA platform for searching and analyzing publicly available online data to detect potential security threats515
sk4la/plastA modular threat-hunting tool framework for detecting indicators of compromise in incident-response operations.17
netevert/sentinel-attackA tool to quickly deploy a threat hunting capability on Azure Sentinel using Sysmon and MITRE ATT&CK1,062
phantomcyber/playbooksCommunity-developed playbooks and custom functions for Splunk SOAR threat hunting and incident response478
sapphirex00/threat-huntingA collection of threat intelligence resources and tools for analyzing APT malware257
stamusnetworks/kts7Templates and dashboards for threat hunting with Suricata IDPS/NSM and the ELK 7 stack40