ashwin-patil / threat-hunting-with-notebooksView external linksLinks
Repository with Sample threat hunting notebooks on Security Event Log Data Sources
☆69Dec 2, 2022Updated 3 years ago
Alternatives and similar repositories for threat-hunting-with-notebooks
Users that are interested in threat-hunting-with-notebooks are comparing it to the libraries listed below
Sorting:
- A repository of curated lists with elements such as IoCs to use for threat hunting & detection queries.☆33Jul 23, 2024Updated last year
- Collection of Jupyter Notebook for Threat Hunting and Blue Team Purposes☆22Jun 15, 2022Updated 3 years ago
- Powershell collection designed to assist in Threat Hunting Windows systems.☆27Apr 13, 2018Updated 7 years ago
- Library of threat hunts to get any user started!☆48Sep 4, 2020Updated 5 years ago
- ☆19Sep 3, 2021Updated 4 years ago
- A community event for security researchers to share their favorite notebooks☆108Feb 15, 2024Updated 2 years ago
- Repository with Sample KQL Query examples for Threat Hunting☆215Sep 1, 2022Updated 3 years ago
- ☆20May 10, 2023Updated 2 years ago
- Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.☆207Jul 21, 2022Updated 3 years ago
- Simple Script to Help You Find All Files Has Been Modified, Accessed, and Created In A Range Time.☆27Dec 1, 2022Updated 3 years ago
- The Threat Hunting In Rapid Iterations (THIRI) Jupyter notebook is designed as a research aide to let you rapidly prototype threat huntin…☆154Apr 25, 2022Updated 3 years ago
- Ekoparty's BlueSpace Keynote November 2021. Shoutout to @plugxor Muchas Gracias!!!☆13Jun 5, 2023Updated 2 years ago
- Detection Engineering research, open-source tools, conference presentations, and technical publications shared with the security communit…☆28Dec 17, 2025Updated 2 months ago
- Modular command-line threat hunting tool & framework.☆17Jul 20, 2020Updated 5 years ago
- Three datasets to practice Threat Hunting against.☆46Jan 3, 2024Updated 2 years ago
- JSON DataSet for macOS mapped to MITRE ATT&CK Tactics.☆158Sep 10, 2021Updated 4 years ago
- Personal compilation of APT malware from whitepaper releases, documents and own research☆266Feb 7, 2019Updated 7 years ago
- Security information and event management, masters's diploma☆10Aug 3, 2015Updated 10 years ago
- Simple yara rule manager☆66Dec 27, 2022Updated 3 years ago
- Repository containing Jupyter Notebooks for working with OSQuery tables and data☆17May 8, 2020Updated 5 years ago
- Resources for SANS CTI Summit 2021 presentation☆104Nov 8, 2023Updated 2 years ago
- This repo is where I store my Threat Hunting ideas/content☆88May 9, 2023Updated 2 years ago
- ☆66May 13, 2022Updated 3 years ago
- Collection of Jupyter Notebooks by @fr0gger_☆191Dec 16, 2025Updated 2 months ago
- Place for resources used during the Mordor Detection hackathon event featuring APT29 ATT&CK evals datasets☆145Oct 12, 2020Updated 5 years ago
- ☆16Apr 30, 2024Updated last year
- Creating a Feed of MISP Events from ThreatFox (by abuse.ch)☆19Jun 2, 2021Updated 4 years ago
- Metadefender Core (Metascan v.4 and v.3) analysis module for Viper malware analysis framework☆10Jan 6, 2021Updated 5 years ago
- An HTTP proxy library for Go☆17Jun 22, 2022Updated 3 years ago
- Searches For Threat Hunting and Security Analytics☆238Mar 26, 2025Updated 10 months ago
- Decentralized Cyber Threat Intelligence Kaizen Framework☆27Jan 31, 2022Updated 4 years ago
- Azure AD Incident Response☆27Oct 8, 2021Updated 4 years ago
- R-CSIRT Linux Triage tool☆39Jun 28, 2018Updated 7 years ago
- Next major release of sniffMyPackets - Now with added packet loving☆12Mar 19, 2015Updated 10 years ago
- All my POC related to malware development☆14May 13, 2024Updated last year
- Debian10-Linux4.19 Hook sys_call_table By IDT☆11May 9, 2020Updated 5 years ago
- evtx2json extracts events of interest from event logs, dedups them, and exports them to json.☆41May 3, 2021Updated 4 years ago
- ☆11Dec 9, 2025Updated 2 months ago
- An ARP based Operating System version scanner☆14Jan 21, 2013Updated 13 years ago