Threat Hunting queries of multiple platforms
☆81Aug 13, 2026Updated this week
Alternatives and similar repositories for Threat-Hunting
Users that are interested in Threat-Hunting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A public repository of quality research on cyber attack techniques. This is the backend for the Technique Research Report (TRR) Library.☆29Updated this week
- A collection of CQL hunting leads for CrowdStrike Falcon and LogScale, mapped to the MITRE ATT&CK framework.☆35May 25, 2026Updated 2 months ago
- An Obsidian-Based Second Brain for CyberSecurity Analysts and Professionals☆61Feb 18, 2026Updated 6 months ago
- Visualize Microsoft Defender XDR process trees and security events☆33Aug 24, 2025Updated 11 months ago
- CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. All queries stored here …☆76Jul 29, 2026Updated 2 weeks ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- This repository contains various threat hunting tools written in Python and is documented in the series Python Threat Hunting Tools which…☆19Nov 16, 2023Updated 2 years ago
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆34Feb 10, 2026Updated 6 months ago
- DetectPack Forge turns plain-English behaviors or sample logs into production-ready detection packs — Sigma, KQL (Sentinel), SPL (Splunk)…☆24Mar 19, 2026Updated 4 months ago
- Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.☆235Updated this week
- Desktop KQL query builder for Microsoft security and Azure services - 52 tables across Defender, Sentinel, Entra ID, Azure Monitor, App I…☆46Jun 22, 2026Updated last month
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆154Jul 28, 2026Updated 2 weeks ago
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Jul 28, 2026Updated 3 weeks ago
- ☆30Oct 13, 2025Updated 10 months ago
- A collection of Claude Code skills that help security teams stay secure☆52Apr 27, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆56Aug 11, 2026Updated last week
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆131Dec 28, 2025Updated 7 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated last year
- Automatic, fast parsing of browser artifacts☆17Jan 4, 2025Updated last year
- Awesome Security lists for SOC/CERT/CTI☆1,858Updated this week
- ☆21Jul 13, 2026Updated last month
- This repository contains Community and Field contributed content for LogScale☆346May 11, 2026Updated 3 months ago
- A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representat…☆54Updated this week
- A multi-mode terminal AI agent supporting GPT-5/Ollama for vision, image creation and edition, video generation,web search, code generati…☆18May 27, 2026Updated 2 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- FireEye iSIGHT Alert Feeder for TheHive, an Open Source and Free Security Incident Response Platform☆16Oct 12, 2018Updated 7 years ago
- Cyber Threat Intelligence☆83Dec 7, 2025Updated 8 months ago
- Indicators of Normality☆11Jul 22, 2022Updated 4 years ago
- Persist like a Dodder☆69May 19, 2025Updated last year
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆151Sep 21, 2024Updated last year
- Web-based IOC management platform with threat intelligence enrichment for SOC teams☆22Jun 20, 2026Updated last month
- Framework for Monitoring File Ingestion Source for Yara Matches☆52Mar 10, 2025Updated last year
- This project provides a set of Google Apps Scripts designed to help you identify and analyze potentially malicious domains directly from …☆14Sep 4, 2024Updated last year
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Agentic memory for CTI in Python — STIX knowledge graphs, threat-actor alias resolution, offline-first RAG, MCP server for Claude Code an…☆58Updated this week
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆158Apr 1, 2026Updated 4 months ago
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆343Dec 3, 2025Updated 8 months ago
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆54Oct 23, 2024Updated last year
- PowerShell tool for streamlined Microsoft Defender Advanced Hunting query management with GitHub Copilot integration☆19Aug 10, 2026Updated last week
- A unified investigation cockpit built for CSIRT / SOC / DFIR teams. Ingest, correlate and visualise any forensic source in a real-time in…☆40Updated this week
- ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.☆361Aug 7, 2026Updated last week