Placeholder for my detection repo and misc detection engineering content
☆43Oct 20, 2023Updated 2 years ago
Alternatives and similar repositories for detections
Users that are interested in detections are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Signature-based detection of malware features based on Windows API call sequences. It's like YARA for sandbox API traces!☆85Jun 28, 2023Updated 3 years ago
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆23Apr 16, 2021Updated 5 years ago
- A collection of my yara rules☆34Jul 11, 2023Updated 3 years ago
- A command-line tool for parsing Windows Master File Table ($MFT) and importing the results into Elasticsearch.☆12Updated this week
- Generates a detailed CSV file containing Sigma Rules statistics for each service or category, and each level, offering a holistic view of…☆10Dec 22, 2023Updated 2 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- ☆264May 9, 2024Updated 2 years ago
- A Compiler from Sigma rules to VQL☆20May 18, 2026Updated 4 months ago
- Scripts and lists to help generate YARA friendly string mutations☆22Apr 9, 2023Updated 3 years ago
- Indicators of compromise from to analysis and research by Nextron Threat Research team☆17Sep 10, 2026Updated 2 weeks ago
- Default Detections for EDR☆96Feb 20, 2024Updated 2 years ago
- Yara rules☆22Mar 27, 2023Updated 3 years ago
- Sigma detection rules for hunting with the threathunting-keywords project☆60Mar 2, 2025Updated last year
- ☆53Oct 27, 2023Updated 2 years ago
- ☆45Jul 11, 2025Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Repository of Volatility3 plugins☆23Mar 22, 2023Updated 3 years ago
- Research into Undocumented Behavior of Azure AD Refresh Tokens☆13Oct 27, 2023Updated 2 years ago
- A repository to share publicly available Velociraptor detection content☆206Updated this week
- A little tool to filter the stranger strings from a binary so you can analyze the good ones☆54Sep 11, 2025Updated last year
- Predicting the probability of an exploit being released after a CVE is published (by Machine learning algorithm)☆13Aug 8, 2023Updated 3 years ago
- Lists of unsafe words in multiple languages as YARA rules☆29Feb 2, 2026Updated 7 months ago
- Conceptual Methods for Finding Commonalities in Macho Files☆13Mar 21, 2024Updated 2 years ago
- A collection of small scripts and tools for deobfuscation and malware analysis.☆67Mar 27, 2023Updated 3 years ago
- Presentation slides, blogs, and videos of my conference presentations.☆26Jan 31, 2024Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Bloodhound Portable for Windows☆55Apr 1, 2023Updated 3 years ago
- Utility tool to ingest CSV files into Kusto☆21Dec 17, 2025Updated 9 months ago
- ☆84Sep 2, 2026Updated 3 weeks ago
- Indicators of compromise☆19May 18, 2026Updated 4 months ago
- ☆41Aug 22, 2025Updated last year
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆60Jan 18, 2023Updated 3 years ago
- Threat intelligence or Cyber Threat Intelligence is the process of identifying and analyzing gathered information about past, current, an…☆13Feb 18, 2024Updated 2 years ago
- ☆33Feb 26, 2022Updated 4 years ago
- ☆13Apr 17, 2022Updated 4 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Scans the filesystem for directories that are user-writeable☆13Jun 21, 2021Updated 5 years ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆21Jul 1, 2023Updated 3 years ago
- ☆21Mar 4, 2025Updated last year
- Microsoft Signed PowerShell scripts☆220Mar 14, 2023Updated 3 years ago
- YETI (Your Everyday Threat Intelligence) Integration to Elastic Stack☆16Jan 6, 2021Updated 5 years ago
- Modifies machine.config for persistence after installing signed .net assembly onto GAC☆12Mar 17, 2022Updated 4 years ago
- Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).☆822Aug 14, 2026Updated last month