A scalable file analysis and data generation platform that allows users to easily orchestrate arbitrary docker/vm/shell tools at scale.
☆1,010Jul 7, 2026Updated 3 weeks ago
Alternatives and similar repositories for thorium
Users that are interested in thorium are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Playbook-NG is a stateless web-based application used to match incident findings with countermeasures for adversary containment and evict…☆163Jul 10, 2026Updated 3 weeks ago
- A simple-to-use IR (incident response) case management tool for tracking and documenting investigations.☆460Apr 29, 2026Updated 3 months ago
- UAC is a powerful and extensible incident response tool designed for forensic investigators, security analysts, and IT professionals. It …☆1,426Jul 1, 2026Updated last month
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆319May 14, 2026Updated 2 months ago
- Automation to assess the state of your M365 tenant against CISA's baselines☆2,632Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV outp…☆331Feb 26, 2026Updated 5 months ago
- A Kubernetes Forensic Collection Framework for Azure Kubernetes Service☆43Feb 9, 2026Updated 5 months ago
- An index of publicly available and open-source threat detection rulesets.☆136Apr 17, 2025Updated last year
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,280Updated this week
- Digging Deeper....☆4,144Updated this week
- Generate realistic synthetic security logs for cybersecurity threat hunting training and research☆198Updated this week
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,617Updated this week
- CRADLE is a collaborative platform for Cyber Threat Intelligence analysts. It streamlines threat investigations with integrated note-taki…☆344May 18, 2026Updated 2 months ago
- Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )☆224Sep 4, 2024Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Main Sigma Rule Repository☆10,837Updated this week
- Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-t…☆1,444May 22, 2026Updated 2 months ago
- Threat-hunting tool for Linux☆1,082Jul 10, 2026Updated 3 weeks ago
- A tool uses Windows Filtering Platform (WFP) to block Endpoint Detection and Response (EDR) agents from reporting security events to the …☆1,896Nov 3, 2024Updated last year
- A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID☆667Jul 6, 2026Updated 3 weeks ago
- LLM Agent Skill for YARA rule authoring and review☆60Feb 8, 2026Updated 5 months ago
- A PowerShell module for acquisition of data from Microsoft 365 and Azure for Incident Response and Cyber Security purposes.☆834Jun 29, 2026Updated last month
- MCP to help Defenders Detection Engineer Harder and Smarter☆467Jun 16, 2026Updated last month
- Misconfiguration Manager is a central knowledge base for all known Microsoft Configuration Manager tradecraft and associated defensive an…☆1,159May 13, 2026Updated 2 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- ☆159Mar 31, 2026Updated 4 months ago
- Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or eve…☆287Jun 23, 2026Updated last month
- A deliberately vulnerable Microsoft Entra ID environment. Learn identity security through hands-on, realistic attack challenges.☆970May 6, 2026Updated 2 months ago
- Rust Library Recognition Project for Rust Malware by the MSTIC-MIRAGE Team☆380Updated this week
- Small and highly portable detection tests based on MITRE's ATT&CK.☆12,346Updated this week
- This project aims to compare and evaluate the telemetry of various EDR products.☆1,976Jul 7, 2026Updated 3 weeks ago
- A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.☆275Sep 23, 2025Updated 10 months ago
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆151Sep 21, 2024Updated last year
- A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat in…☆571Updated this week
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Python implementation of the CaRT library for (un)inerting files.☆53Feb 10, 2025Updated last year
- Malware Configuration And Payload Extraction☆3,403Updated this week
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆2,467Updated this week
- Your Browser-based EVTX Companion☆123Jul 21, 2026Updated last week
- LotL RMM☆382Jul 15, 2026Updated 2 weeks ago
- AssemblyLine 4: File triage and malware analysis☆522Updated this week
- The MAGIC tool is a wrapper around the Microsoft Graph Python SDK, designed to download incident response-relevant data from M365 environ…☆35Apr 13, 2026Updated 3 months ago