HarfangLab / iocs
Indicators of compromise
☆12Updated 3 weeks ago
Alternatives and similar repositories for iocs:
Users that are interested in iocs are comparing it to the libraries listed below
- ☆35Updated last week
- Contains compiled binaries of Volatility☆33Updated 3 months ago
- Sigma detection rules for hunting with the threathunting-keywords project☆55Updated 2 months ago
- Rapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence…☆60Updated last month
- An introduction to detection engineering☆13Updated 4 months ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆33Updated last week
- Tools and scripts to deploy and manage OpenRelik instances☆13Updated 2 months ago
- A specification and style guide for YARA rules☆48Updated last year
- Finding ClickFix and FakeCAPTCHA like it's 1999☆35Updated this week
- VelociraptorMCP is a Model Context Protocol bridge for exposing LLMs to MCP clients.☆23Updated this week
- Turn any blog into structured threat intelligence.☆26Updated last week
- Yara Rules for Modern Malware☆77Updated last year
- ☆22Updated 3 months ago
- CarbonBlack EDR detection rules and response actions☆71Updated 8 months ago
- Quick ESXi Log Parser☆19Updated 4 months ago
- Placeholder for my detection repo and misc detection engineering content☆43Updated last year
- Repo that hold write-ups of various research projects I did and/or overall InfoSec things I investigated/researched.☆20Updated 4 months ago
- Jupyter Notebooks for Cyber Threat Intelligence☆35Updated last year
- Security Content for the PEAK Threat Hunting Framework☆28Updated last year
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆78Updated 8 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆84Updated 3 months ago
- This project aims to bridge the gap between Microsoft Attack Surface Reduction (ASR) rules and MITRE ATT&CK by mapping ASR rules to their…☆26Updated 5 months ago
- The home of the SDDLMaker☆15Updated 3 months ago
- TIM is a Kusto investigation platform that enables a user to quickly pivot between data sources; annotate their findings; and promotes co…☆21Updated 9 months ago
- Raw data from Threat Intelligence Reports with automatic reports collection and keyword search across thousands of reports☆113Updated this week
- Velociraptor Server hosted in Azure App Service☆38Updated this week
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆51Updated 6 months ago
- Active C&C Detector☆154Updated last year
- A repository to help CTI teams tackle the challenges around collection and research by providing guidance from experienced practitioners☆88Updated 6 months ago
- ☆21Updated 2 years ago