ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.
☆364Aug 26, 2026Updated this week
Alternatives and similar repositories for agentic-threat-hunting-framework
Users that are interested in agentic-threat-hunting-framework are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An AI-backed threat hunting assistant that aligns to the PEAK framework.☆60Jun 1, 2026Updated 2 months ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆339Updated this week
- AI 驱动的 SOC 仿真平台☆166Jan 2, 2026Updated 7 months ago
- MCP to help Defenders Detection Engineer Harder and Smarter☆475Jun 16, 2026Updated 2 months ago
- Agentic SOC Platform: A powerful, flexible, open-source, and agent-centric automated security operations platform (AI SOC)☆1,162Aug 5, 2026Updated 3 weeks ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A minimal, modular MCP server that equips your AI with practical capabilities for real-world threat hunting workflows.☆19Apr 26, 2026Updated 4 months ago
- Generate realistic synthetic security logs for cybersecurity threat hunting training and research☆222Updated this week
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆321May 14, 2026Updated 3 months ago
- A collection of CQL hunting leads for CrowdStrike Falcon and LogScale, mapped to the MITRE ATT&CK framework.☆35May 25, 2026Updated 3 months ago
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆344Updated this week
- Run TTPs, with AI!☆141Feb 23, 2026Updated 6 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated last year
- Awesome Security lists for SOC/CERT/CTI☆1,894Updated this week
- PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via …☆168Jan 25, 2026Updated 7 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Free educational content on reverse engineering and malware analysis from the FLARE team☆1,438Mar 31, 2026Updated 4 months ago
- Web-based IOC management platform with threat intelligence enrichment for SOC teams☆22Jun 20, 2026Updated 2 months ago
- how to strangle threats☆61Updated this week
- PowerShell tools to help defenders hunt smarter, hunt harder.☆490Oct 29, 2025Updated 9 months ago
- ☆38Updated this week
- Vigil: the open source AI SOC (agentic SOC). 13 specialized AI agents, 30+ MCP integrations, 7,200+ detection rules. Apache 2.0.☆266Updated this week
- This repository contains detailed adversary simulation APT campaigns targeting various critical sectors. Each simulation includes custom …☆1,121Aug 3, 2026Updated 3 weeks ago
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆158Apr 1, 2026Updated 4 months ago
- A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based be…☆267Aug 6, 2026Updated 3 weeks ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Detection Reliability And Precision Efficiency (DRAPE) is an index used to assess detection performance☆36Nov 17, 2025Updated 9 months ago
- Lists of independent cybersecurity blogs covering threat intelligence, purple team, red team, threat hunting, and detection engineering. …☆41Updated this week
- CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taki…☆344May 18, 2026Updated 3 months ago
- Threat Hunting queries of multiple platforms☆83Aug 13, 2026Updated 2 weeks ago
- A sysmon configuration designed for monitoring RMM solutions from the LOLRMM framework on the OS Microsoft Windows. 10/11☆33Feb 17, 2026Updated 6 months ago
- GenAI-STIX2.1-Generator is a tool that leverages Azure OpenAI capabilities to transform threat intelligence reports from unstructured web…☆24Mar 24, 2025Updated last year
- Threat feeds designed to extract adversarial TTPs and IOCs, using: ✨AI✨☆74Jun 17, 2026Updated 2 months ago
- Mapping of open-source detection rules and atomic tests.☆215Jul 15, 2026Updated last month
- ☆79Jan 1, 2026Updated 7 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- An Obsidian-Based Second Brain for CyberSecurity Analysts and Professionals☆61Feb 18, 2026Updated 6 months ago
- Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techn…☆59Jul 5, 2026Updated last month
- Active C&C Detector☆156Oct 5, 2023Updated 2 years ago
- Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.☆243Updated this week
- AI-powered cybersecurity attack flow visualization tool using MITRE ATT&CK☆236Jul 18, 2026Updated last month
- Open-source collaborative note-taking platform for cybersecurity and CTI teams. IOC auto-extraction, STIX 2.1 export, real-time ed…☆23Apr 6, 2026Updated 4 months ago
- Convert Sigma rules to SIEM queries, directly in your browser.☆122Aug 19, 2026Updated last week