APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
☆1,419Nov 7, 2024Updated last year
Alternatives and similar repositories for APT-Hunter
Users that are interested in APT-Hunter are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Windows Events Attack Samples☆2,624Jan 24, 2023Updated 3 years ago
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,655Aug 25, 2026Updated last week
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆850Aug 24, 2026Updated 2 weeks ago
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,335Updated this week
- Investigate malicious Windows logon by visualizing and analyzing Windows event log☆3,232Aug 2, 2026Updated last month
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆663Jun 19, 2024Updated 2 years ago
- WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)☆775Feb 3, 2023Updated 3 years ago
- A toolset to make a system look as if it was the victim of an APT attack☆2,766Sep 23, 2025Updated 11 months ago
- Scan files or process memory for CobaltStrike beacons and parse their configuration☆918Aug 19, 2021Updated 5 years ago
- Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, M…☆4,082Aug 7, 2026Updated last month
- ☆1,136Dec 19, 2023Updated 2 years ago
- ☆2,429Oct 14, 2023Updated 2 years ago
- Defences against Cobalt Strike☆1,301Jul 14, 2022Updated 4 years ago
- Interesting APT Report Collection And Some Special IOCs☆3,086Updated this week
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).☆825Aug 14, 2026Updated 3 weeks ago
- Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows…☆2,139Dec 11, 2024Updated last year
- Utilities for Sysmon☆1,661Apr 4, 2026Updated 5 months ago
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,652Jan 12, 2026Updated 7 months ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆641May 21, 2026Updated 3 months ago
- Open Source EDR for Windows☆1,314Feb 25, 2023Updated 3 years ago
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆870Jan 20, 2022Updated 4 years ago
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆1,077Oct 5, 2023Updated 2 years ago
- A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365☆794Oct 29, 2022Updated 3 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Main Sigma Rule Repository☆10,989Updated this week
- Detect Tactics, Techniques & Combat Threats☆2,337Aug 6, 2026Updated last month
- Threat Hunting tool about Sysmon and graphs☆342May 28, 2023Updated 3 years ago
- Documentation and scripts to properly enable Windows event logs.☆718Oct 3, 2025Updated 11 months ago
- Elastic Security detection content for Endpoint☆1,489Updated this week
- Digging Deeper....☆4,236Updated this week
- A repository of sysmon configuration modules☆3,128Aug 31, 2026Updated last week
- DFIRTrack - The Incident Response Tracking Application☆538Jan 13, 2026Updated 7 months ago
- Small and highly portable detection tests based on MITRE's ATT&CK.☆12,489Updated this week
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Loki - Simple IOC and YARA Scanner☆3,788Jan 12, 2026Updated 7 months ago
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆552Sep 2, 2022Updated 4 years ago
- Re-play Security Events☆1,810Mar 20, 2024Updated 2 years ago
- Hunts out CobaltStrike beacons and logs operator command output☆964Sep 4, 2024Updated 2 years ago
- Misc Threat Hunting Resources☆377Jan 26, 2023Updated 3 years ago
- Incident Response - Fast suspicious file finder☆261Jan 24, 2026Updated 7 months ago
- A curated list of tools for incident response☆9,373Jul 15, 2026Updated last month