A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale.
☆1,024Sep 21, 2026Updated last week
Alternatives and similar repositories for thorium
Users that are interested in thorium are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Playbook-NG is a stateless web-based application used to match incident findings with countermeasures for adversary containment and evict…☆164Aug 21, 2026Updated last month
- A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.☆465Apr 29, 2026Updated 5 months ago
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,471Sep 9, 2026Updated 3 weeks ago
- Automation to assess the state of your M365 tenant against CISA's baselines☆2,690Updated this week
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆323May 14, 2026Updated 4 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A Kubernetes Forensic Collection Framework for Azure Kubernetes Service☆44Feb 9, 2026Updated 7 months ago
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,376Updated this week
- Digging Deeper....☆4,288Updated this week
- An index of publicly available and open-source threat detection rulesets.☆141Apr 17, 2025Updated last year
- Generate realistic synthetic security logs for cybersecurity threat hunting training and research☆271Updated this week
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,680Sep 23, 2026Updated last week
- CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taki…☆341May 18, 2026Updated 4 months ago
- Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )☆224Sep 4, 2024Updated 2 years ago
- Main Sigma Rule Repository☆11,144Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-t…☆1,445May 22, 2026Updated 4 months ago
- Threat-hunting tool for Linux☆1,092Updated this week
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,911Nov 3, 2024Updated last year
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆679Jul 6, 2026Updated 2 months ago
- LLM Agent Skill for YARA rule authoring and review☆59Feb 8, 2026Updated 7 months ago
- A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.☆856Jun 29, 2026Updated 3 months ago
- Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive an…☆1,169Sep 16, 2026Updated 2 weeks ago
- ☆163Mar 31, 2026Updated 6 months ago
- Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or eve…☆290Jun 23, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- MCP to help Defenders Detection Engineer Harder and Smarter☆495Jun 16, 2026Updated 3 months ago
- Rust Library Recognition Project for Rust Malware by the MSTIC-MIRAGE Team☆385Sep 4, 2026Updated 3 weeks ago
- A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.☆987May 6, 2026Updated 4 months ago
- This project aims to compare and evaluate the telemetry of various EDR products.☆1,991Updated this week
- Small and highly portable detection tests based on MITRE's ATT&CK.☆12,604Updated this week
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆151Sep 21, 2024Updated 2 years ago
- Python implementation of the CaRT library for (un)inerting files.☆55Feb 10, 2025Updated last year
- A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat in…☆616Updated this week
- Malware Configuration And Payload Extraction☆3,545Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆2,535Updated this week
- A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.☆285Sep 23, 2025Updated last year
- Your Browser-based EVTX Companion☆124Jul 21, 2026Updated 2 months ago
- AssemblyLine 4: File triage and malware analysis☆547Updated this week
- LotL RMM☆404Updated this week
- A resource containing all the tools each ransomware gangs uses☆1,451Aug 29, 2026Updated last month
- Documentation and scripts to properly enable Windows event logs.☆723Oct 3, 2025Updated 11 months ago