APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity
☆1,411Nov 7, 2024Updated last year
Alternatives and similar repositories for APT-Hunter
Users that are interested in APT-Hunter are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Windows Events Attack Samples☆2,560Jan 24, 2023Updated 3 years ago
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,554May 9, 2026Updated 2 weeks ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆812May 15, 2026Updated 2 weeks ago
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,169May 20, 2026Updated last week
- Investigate malicious Windows logon by visualizing and analyzing Windows event log☆3,177Apr 22, 2026Updated last month
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Collection of Event ID ressources useful for Digital Forensics and Incident Response☆652Jun 19, 2024Updated last year
- WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)☆777Feb 3, 2023Updated 3 years ago
- A toolset to make a system look as if it was the victim of an APT attack☆2,745Sep 23, 2025Updated 8 months ago
- Scan files or process memory for CobaltStrike beacons and parse their configuration☆920Aug 19, 2021Updated 4 years ago
- Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, M…☆3,835Apr 16, 2026Updated last month
- ☆1,135Dec 19, 2023Updated 2 years ago
- Defences against Cobalt Strike☆1,303Jul 14, 2022Updated 3 years ago
- ☆2,408Oct 14, 2023Updated 2 years ago
- Interesting APT Report Collection And Some Special IOCs☆3,000Updated this week
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Powershell module that can be used by Blue Teams, Incident Responders and System Administrators to hunt persistences implanted in Windows…☆2,122Dec 11, 2024Updated last year
- Utilities for Sysmon☆1,645Apr 4, 2026Updated last month
- Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).☆814Jan 14, 2026Updated 4 months ago
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,568Jan 12, 2026Updated 4 months ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆629May 21, 2026Updated last week
- Open Source EDR for Windows☆1,304Feb 25, 2023Updated 3 years ago
- Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detection…☆866Jan 20, 2022Updated 4 years ago
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆1,071Oct 5, 2023Updated 2 years ago
- Main Sigma Rule Repository☆10,480May 22, 2026Updated last week
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Documentation and scripts to properly enable Windows event logs.☆704Oct 3, 2025Updated 7 months ago
- A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365☆790Oct 29, 2022Updated 3 years ago
- Detect Tactics, Techniques & Combat Threats☆2,292Apr 29, 2026Updated last month
- Threat Hunting tool about Sysmon and graphs☆339May 28, 2023Updated 3 years ago
- Small and highly portable detection tests based on MITRE's ATT&CK.☆11,994Updated this week
- Elastic Security detection content for Endpoint☆1,433May 20, 2026Updated last week
- A repository of sysmon configuration modules☆3,045Aug 21, 2024Updated last year
- Digging Deeper....☆3,973May 22, 2026Updated last week
- DFIRTrack - The Incident Response Tracking Application☆534Jan 13, 2026Updated 4 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆549Sep 2, 2022Updated 3 years ago
- Loki - Simple IOC and YARA Scanner☆3,756Jan 12, 2026Updated 4 months ago
- Re-play Security Events☆1,757Mar 20, 2024Updated 2 years ago
- Hunts out CobaltStrike beacons and logs operator command output☆958Sep 4, 2024Updated last year
- Misc Threat Hunting Resources☆379Jan 26, 2023Updated 3 years ago
- Incident Response - Fast suspicious file finder☆255Jan 24, 2026Updated 4 months ago
- A curated list of tools for incident response☆9,052May 6, 2026Updated 3 weeks ago