plast

Threat detection framework

A modular threat-hunting tool framework for detecting indicators of compromise in incident-response operations.

Modular command-line threat hunting tool & framework.

GitHub

17 stars
2 watching
4 forks
Language: Python
last commit: about 6 years ago
Linked from 1 awesome list

aptdigital-forensicsframeworkincident-responseiocpythonpython3threat-huntingyara

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
opencybersecurityalliance/kestrel-langA language and runtime framework for building reusable, composable threat hunting workflows using Python.302
a3sal0n/cyberthreathuntingA collection of tools and resources for threat hunters to identify and respond to cyber threats.861
threathuntingproject/threathuntingAn informational repository providing resources and knowledge for detecting adversaries in IT environments.1,726
atc-project/atomic-threat-coverageA framework for generating actionable analytics to combat threats based on threat modeling and incident response975
cred-club/artifAn advanced threat intelligence framework that integrates real-time IP reputation and historical data analysis to identify malicious traffic239
matamorphosis/scrummageA platform for searching and analyzing publicly available online data to detect potential security threats515
ptr32void/ostricaA framework to collect and visualize threat intelligence information from various sources in a flexible and plugin-based architecture.309
stratosphereips/manatiAn open-source tool utilizing machine learning to assist threat analysts in identifying security problems.112
owasp/pytmAutomates threat modeling and documentation for software systems.934
sbousseaden/slidesCollection of resources and concepts for threat hunting and detection engineering.372
kunai-project/kunaiAn eBPF-based tool for comprehensive Linux event monitoring and analysis403
anvilogic-forge/armoryA collection of threat detection methodologies and tools to help security teams identify and respond to emerging threats.88
west-wind/threat-hunting-with-splunkProvides Splunk queries to detect vulnerability exploitation attempts and subsequent compromise, including threat hunting for MITRE ATT&CK TTPs58
miladaslaner/threathuntA PowerShell repository to simulate and train threat hunting skills without malicious files.134
kevthehermit/pastehunterAutomates scanning of publicly hosted pasted data against Yara rules to identify potential security or research threats.1,069