avast / ioc
Threat Intel IoCs + bits and pieces of dark matter
☆393Updated 3 months ago
Alternatives and similar repositories for ioc:
Users that are interested in ioc are comparing it to the libraries listed below
- Sophos-originated indicators-of-compromise from published reports☆565Updated 2 weeks ago
- A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.☆370Updated 2 years ago
- Automatically created C2 Feeds☆584Updated this week
- Repository of YARA rules made by Trellix ATR Team☆576Updated last year
- ☆514Updated 4 months ago
- ☆535Updated last year
- ☆130Updated last year
- ReversingLabs YARA Rules☆791Updated last month
- Analysis of malware and Cyber Threat Intel of APT and cybercriminals groups☆707Updated 2 years ago
- PCAP Samples for Different Post Exploitation Techniques☆354Updated 3 years ago
- Standard collection of rules for capa: the tool for enumerating the capabilities of programs☆566Updated 2 weeks ago
- Indicators from Unit 42 Public Reports☆707Updated 3 weeks ago
- Code and yara rules to detect and analyze Cobalt Strike☆265Updated 3 years ago
- Collection of private Yara rules.☆340Updated this week
- Test the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-Cradle…☆296Updated 3 years ago
- A collection of red team and adversary emulation resources developed and released by MITRE.☆498Updated 3 years ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆700Updated 2 weeks ago
- Sigma rules from Joe Security☆206Updated 3 months ago
- IOC from articles, tweets for archives☆313Updated last year
- ☆1,044Updated last year
- Extract and Deobfuscate XLM macros (a.k.a Excel 4.0 Macros)☆575Updated 9 months ago
- Ransomware simulator written in Golang☆424Updated 2 years ago
- Signatures and IoCs from public Volexity blog posts.☆348Updated last week
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆550Updated last month
- Live forensic artifacts collector☆165Updated 7 months ago
- Distributed malware processing framework based on Python, Redis and S3.☆401Updated 3 weeks ago
- Threat Hunting tool about Sysmon and graphs☆330Updated last year
- Detect and respond to Cobalt Strike beacons using ETW.☆486Updated 2 years ago
- Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.☆243Updated 2 years ago
- YARA Rules I come across on the internet☆337Updated 10 months ago