This repository contains OpenIOC rules to aid in hunting for indicators of compromise and TTPs focused on Advanced Persistent Threat groups.
☆26Oct 3, 2023Updated 2 years ago
Alternatives and similar repositories for APT-OpenIOC-Detection-Rules
Users that are interested in APT-OpenIOC-Detection-Rules are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An experimental Velociraptor implementation using cloud infrastructure☆26Aug 25, 2026Updated last week
- yara detection rules for hunting with the threathunting-keywords project☆166May 11, 2025Updated last year
- A dataset containing APT group related articles and MITRE ATT&CK technique descriptions☆18Aug 14, 2019Updated 7 years ago
- APT hub, It help's research to collect information and data on the latest APT activities. It collects data on APT profiles, IOCs(1 yr), a…☆56Mar 11, 2025Updated last year
- CLI generator for Velociraptor offline collector☆17Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆17Mar 13, 2026Updated 5 months ago
- SIEM Cheat Sheet☆84Aug 15, 2023Updated 3 years ago
- Listing of YARA rules I wrote for Live and Retro hunts. Includes Jupyter infostealer, suspicious powershell, dll hijacking, vbs downloade…☆17Jun 26, 2026Updated 2 months ago
- Position and velocity PID control of a DC motor using LabView and Arduino☆15Apr 23, 2018Updated 8 years ago
- ☆15Jul 20, 2022Updated 4 years ago
- KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.☆25Nov 7, 2024Updated last year
- PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.☆37Jul 11, 2023Updated 3 years ago
- Thor Artifacts for Velociraptor☆19Dec 2, 2025Updated 9 months ago
- a database that collects data related to APTs from existing public sources through a semi automatic methodology and produces an exhaustiv…☆21Nov 22, 2022Updated 3 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- APT-KGL: An Intelligent APT Detection System Based on Threat Knowledge and Heterogeneous Provenance Graph Learning☆78Jul 8, 2022Updated 4 years ago
- Threat Detection System using Hybrid (Machine Learning + Lexical Analysis) learning Approach.☆11May 30, 2017Updated 9 years ago
- KQL Sentinel and Defender Detection and Hunting Queries.☆16Aug 17, 2026Updated 2 weeks ago
- Rules Shared by the Community from 100 Days of YARA 2023 -☆19Apr 10, 2023Updated 3 years ago
- All in one - Malware + Analysis by Cylance☆11Nov 23, 2018Updated 7 years ago
- Splunk Queries for SOC Analyst☆17Jan 25, 2024Updated 2 years ago
- A heuristic, python-based detector for fast-flux botnets.☆13Feb 24, 2012Updated 14 years ago
- Evolutionary decision trees☆11Jun 16, 2025Updated last year
- Implement a VAE to learn a reduced state space representation from the NSL-KDD dataset, capturing essential features of normal network t…☆14Feb 15, 2024Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Splunk TA for sending completion requests to ChatGPT☆27Jun 12, 2026Updated 2 months ago
- A collection of companies that disclose adversary TTPs after they have been breached☆305Jun 7, 2026Updated 2 months ago
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆109Mar 12, 2026Updated 5 months ago
- Hunt the windows Registry automatically using VQL☆18Aug 7, 2026Updated 3 weeks ago
- Legacy Sigma Tools (sigmac etc.)☆17May 7, 2023Updated 3 years ago
- PowerShell Memory Pulling script☆19Mar 24, 2015Updated 11 years ago
- Roota is a public-domain language of threat detection and response that combines native queries from a SIEM, EDR, XDR, or Data Lake with …☆140Jul 19, 2024Updated 2 years ago
- Digital Forensics Artifacts Knowledge Base☆90May 16, 2026Updated 3 months ago
- Threat Hunting Malware Infrastructure☆12Dec 3, 2023Updated 2 years ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection☆33Oct 7, 2020Updated 5 years ago
- Red Team tool for exfiltrating files from a target's Google Drive that you have access to, via Google's API.☆60Sep 2, 2021Updated 5 years ago
- Exporting MISP event attributes to yara rules usable with Thor apt scanner☆25Mar 27, 2017Updated 9 years ago
- Alternative password shadowing scheme☆12Aug 1, 2026Updated last month
- ☆11Feb 9, 2023Updated 3 years ago
- Threat Feeds, Threat lists, and regular lists of known IP ranges and domains. It updates every 4 hours.☆16May 21, 2021Updated 5 years ago
- Analyse metabolic stability predictions using SHapley Additive exPlanations.☆11Jul 26, 2023Updated 3 years ago