Recon Hunt Queries
☆78May 16, 2021Updated 5 years ago
Alternatives and similar repositories for rhq
Users that are interested in rhq are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Collection of operational focused osquery dashboards.☆10Jan 20, 2021Updated 5 years ago
- Threat hunting repo for my independent study on threat hunting with OSQuery☆27Jan 16, 2018Updated 8 years ago
- Threat Hunting & Incident Investigation with Osquery☆217Mar 30, 2022Updated 4 years ago
- A Splunk technology add-on for osquery☆14Sep 5, 2025Updated last year
- Creates an ATT&CK Navigator map of an Adversary Emulation Plan☆17Sep 4, 2021Updated 5 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- ☆16Oct 24, 2024Updated last year
- Create alerts in The Hive from your Graylog alerts, to be turned into Hive cases.☆45Aug 17, 2020Updated 6 years ago
- ☆18May 23, 2024Updated 2 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆24Jul 9, 2021Updated 5 years ago
- Detection Ideas & Rules repository.☆179Sep 10, 2021Updated 5 years ago
- Registry to JSON. This Project is for learning purposes and is not maintained.☆12Dec 28, 2021Updated 4 years ago
- Triage automation for suspect URLs☆13Jul 23, 2019Updated 7 years ago
- Dockerfiles for containerized osquery☆14May 23, 2017Updated 9 years ago
- PyVelociraptor contains the python bindings for the Velociraptor API.☆23May 5, 2026Updated 5 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- NTFS file system specimens☆13May 21, 2026Updated 4 months ago
- Repo with supporting material for the talk titled "Cracking the Beacon: Automating the extraction of implant configurations"☆11Feb 6, 2025Updated last year
- The Cold Disk Quick Response (CDQR) tool is a fast and easy to use forensic artifact parsing tool that works on disk images, mounted driv…☆345Jun 25, 2022Updated 4 years ago
- Kibana app for RedELK☆17Mar 19, 2023Updated 3 years ago
- Ansible playbook to convert Sigma rules to ElastAlert rules☆10Feb 5, 2021Updated 5 years ago
- Transform EQL detection rules to VQL artifacts☆12Nov 12, 2021Updated 4 years ago
- Library of threat hunts to get any user started!☆51Sep 4, 2020Updated 6 years ago
- osquery Foundation Charter, Legal, and Process Documents☆15Jun 10, 2022Updated 4 years ago
- Event Trace Log file parser in pure Python☆157May 20, 2026Updated 4 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Searches For Threat Hunting and Security Analytics☆237Mar 26, 2025Updated last year
- ☆20Oct 23, 2020Updated 5 years ago
- A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns by leveraging Windows Events and Sys…☆11Apr 13, 2017Updated 9 years ago
- A specialized environment for crafting, validating, and testing LimaCharlie detection rules☆15Sep 14, 2026Updated 3 weeks ago
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆21Oct 25, 2023Updated 2 years ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆812May 11, 2023Updated 3 years ago
- Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux☆520Oct 21, 2022Updated 3 years ago
- A flexible control server for osquery fleets☆1,098Dec 15, 2020Updated 5 years ago
- TIBER-Cases is a project created to give cases of The Hive platform for Threat Intelligence Analysts mainly. All the cases are mapped to …☆27Jul 13, 2022Updated 4 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ATT&CK Remote Threat Hunting Incident Response☆203Dec 8, 2024Updated last year
- A framework for developing alerting and detection strategies for incident response.☆915Oct 2, 2026Updated last week
- The Intelligent Process Lifecycle of Active Cyber Defenders☆34Jan 1, 2023Updated 3 years ago
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆23Apr 16, 2021Updated 5 years ago
- Automatic detection engineering technical state compliance☆55Jul 7, 2024Updated 2 years ago
- ☆49Aug 30, 2020Updated 6 years ago
- A repository for using osquery for incident detection and response☆907Oct 2, 2026Updated last week