Threat Hunting queries of multiple platforms
☆84Sep 24, 2026Updated this week
Alternatives and similar repositories for Threat-Hunting
Users that are interested in Threat-Hunting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A public repository of quality research on cyber attack techniques. This is the backend for the Technique Research Report (TRR) Library.☆31Sep 1, 2026Updated 3 weeks ago
- A collection of CQL hunting leads for CrowdStrike Falcon and LogScale, mapped to the MITRE ATT&CK framework.☆35Sep 8, 2026Updated 2 weeks ago
- An Obsidian-Based Second Brain for CyberSecurity Analysts and Professionals☆61Feb 18, 2026Updated 7 months ago
- Visualize Microsoft Defender XDR process trees and security events☆33Aug 24, 2025Updated last year
- CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. All queries stored here …☆84Sep 14, 2026Updated last week
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- This repository contains various threat hunting tools written in Python and is documented in the series Python Threat Hunting Tools which…☆22Nov 16, 2023Updated 2 years ago
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆34Feb 10, 2026Updated 7 months ago
- DetectPack Forge turns plain-English behaviors or sample logs into production-ready detection packs — Sigma, KQL (Sentinel), SPL (Splunk)…☆24Mar 19, 2026Updated 6 months ago
- Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.☆247Updated this week
- Desktop KQL query builder for Microsoft security and Azure services - 52 tables across Defender, Sentinel, Entra ID, Azure Monitor, App I…☆47Jun 22, 2026Updated 3 months ago
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆156Jul 28, 2026Updated last month
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Jul 28, 2026Updated last month
- ☆30Oct 13, 2025Updated 11 months ago
- A collection of Claude Code skills that help security teams stay secure☆58Apr 27, 2026Updated 4 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆58Sep 6, 2026Updated 2 weeks ago
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆131Dec 28, 2025Updated 8 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated last year
- Automatic, fast parsing of browser artifacts☆17Jan 4, 2025Updated last year
- Awesome Security lists for SOC/CERT/CTI☆1,921Updated this week
- This repository contains Community and Field contributed content for LogScale☆350Sep 15, 2026Updated last week
- A powerful Python library and CLI tool for parsing, analyzing, and manipulating YARA rules through Abstract Syntax Tree (AST) representat…☆54Sep 13, 2026Updated 2 weeks ago
- Cyber Threat Intelligence☆83Dec 7, 2025Updated 9 months ago
- A multi-mode terminal AI agent supporting GPT-5/Ollama for vision, image creation and edition, video generation,web search, code generati…☆17May 27, 2026Updated 3 months ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- FireEye iSIGHT Alert Feeder for TheHive, an Open Source and Free Security Incident Response Platform☆16Oct 12, 2018Updated 7 years ago
- Indicators of Normality☆11Jul 22, 2022Updated 4 years ago
- Persist like a Dodder☆69May 19, 2025Updated last year
- Web-based IOC management platform with threat intelligence enrichment for SOC teams☆22Jun 20, 2026Updated 3 months ago
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆151Sep 21, 2024Updated 2 years ago
- Framework for Monitoring File Ingestion Source for Yara Matches☆52Mar 10, 2025Updated last year
- ☆22Jul 13, 2026Updated 2 months ago
- This project provides a set of Google Apps Scripts designed to help you identify and analyze potentially malicious domains directly from …☆14Sep 4, 2024Updated 2 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Agentic memory for CTI in Python — STIX knowledge graphs, threat-actor alias resolution, offline-first RAG, MCP server for Claude Code an…☆63Updated this week
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆159Apr 1, 2026Updated 5 months ago
- An easy to use PowerShell script to collect memory and disk forensics for DFIR investigations.☆347Dec 3, 2025Updated 9 months ago
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆54Oct 23, 2024Updated last year
- PowerShell tool for streamlined Microsoft Defender Advanced Hunting query management with GitHub Copilot integration☆21Aug 31, 2026Updated 3 weeks ago
- A unified investigation cockpit built for CSIRT / SOC / DFIR teams. Ingest, correlate and visualise any forensic source in a real-time in…☆43Updated this week
- ☆67Jul 6, 2026Updated 2 months ago