ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.
☆334Jul 14, 2026Updated this week
Alternatives and similar repositories for agentic-threat-hunting-framework
Users that are interested in agentic-threat-hunting-framework are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An AI-backed threat hunting assistant that aligns to the PEAK framework.☆58Jun 1, 2026Updated last month
- AI 驱动的 SOC 仿真平台☆165Jan 2, 2026Updated 6 months ago
- MCP to help Defenders Detection Engineer Harder and Smarter☆462Jun 16, 2026Updated last month
- Agentic SOC Platform: A powerful, flexible, open-source, and agent-centric automated security operations platform (AI SOC)☆956Updated this week
- A minimal, modular MCP server that equips your AI with practical capabilities for real-world threat hunting workflows.☆17Apr 26, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A collection of CQL hunting leads for CrowdStrike Falcon and LogScale, mapped to the MITRE ATT&CK framework.☆33May 25, 2026Updated last month
- Generate realistic synthetic security logs for cybersecurity threat hunting training and research☆190Updated this week
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆329Updated this week
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆321May 14, 2026Updated 2 months ago
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆295Jun 6, 2026Updated last month
- Run TTPs, with AI!☆140Feb 23, 2026Updated 4 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated 11 months ago
- Awesome Security lists for SOC/CERT/CTI☆1,739Updated this week
- PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via …☆166Jan 25, 2026Updated 5 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Free educational content on reverse engineering and malware analysis from the FLARE team☆1,360Mar 31, 2026Updated 3 months ago
- Web-based IOC management platform with threat intelligence enrichment for SOC teams☆22Jun 20, 2026Updated last month
- how to strangle threats☆58Updated this week
- PowerShell tools to help defenders hunt smarter, hunt harder.☆489Oct 29, 2025Updated 8 months ago
- ☆37Updated this week
- Vigil - an ever improving 100% OpenSource AI system for security☆214Updated this week
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆157Apr 1, 2026Updated 3 months ago
- A modular, skill-based autonomous Security Operations Center (SOC) agent that monitors OpenSearch/Elasticsearch data, builds RAG-based be…☆254Updated this week
- Detection Reliability And Precision Efficiency (DRAPE) is an index used to assess detection performance☆36Nov 17, 2025Updated 8 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taki…☆343May 18, 2026Updated 2 months ago
- Threat Hunting queries of multiple platforms☆76Updated this week
- Lists of independent cybersecurity blogs covering threat intelligence, purple team, red team, threat hunting, and detection engineering. …☆39May 9, 2026Updated 2 months ago
- Threat feeds designed to extract adversarial TTPs and IOCs, using: ✨AI✨☆74Jun 17, 2026Updated last month
- A sysmon configuration designed for monitoring RMM solutions from the LOLRMM framework on the OS Microsoft Windows. 10/11☆33Feb 17, 2026Updated 5 months ago
- GenAI-STIX2.1-Generator is a tool that leverages Azure OpenAI capabilities to transform threat intelligence reports from unstructured web…☆24Mar 24, 2025Updated last year
- ☆79Jan 1, 2026Updated 6 months ago
- Cyber Threat Intelligence Capability Maturity Model (CTI-CMM), a dedicated maturity framework to empower your team. Inspired by industry …☆47Jun 3, 2026Updated last month
- An Obsidian-Based Second Brain for CyberSecurity Analysts and Professionals☆59Feb 18, 2026Updated 5 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Aether is a Windows memory-forensics and threat hunting tool that scans live process memory for malicious pattern, detect injection techn…☆55Jul 5, 2026Updated 2 weeks ago
- Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.☆230Updated this week
- AI-powered cybersecurity attack flow visualization tool using MITRE ATT&CK☆229Updated this week
- Open-source collaborative note-taking platform for cybersecurity and CTI teams. IOC auto-extraction, STIX 2.1 export, real-time ed…☆23Apr 6, 2026Updated 3 months ago
- Active C&C Detector☆156Oct 5, 2023Updated 2 years ago
- Purple-team telemetry & simulation toolkit.☆113Dec 16, 2025Updated 7 months ago
- Command and Control Framework using powershell implants☆36Jun 17, 2025Updated last year