This repository contains OpenIOC rules to aid in hunting for indicators of compromise and TTPs focused on Advanced Persistent Threat groups.
☆26Oct 3, 2023Updated 2 years ago
Alternatives and similar repositories for APT-OpenIOC-Detection-Rules
Users that are interested in APT-OpenIOC-Detection-Rules are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An experimental Velociraptor implementation using cloud infrastructure☆26Jun 25, 2026Updated last month
- yara detection rules for hunting with the threathunting-keywords project☆166May 11, 2025Updated last year
- CLI generator for Velociraptor offline collector☆17Jul 15, 2026Updated last week
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆17Mar 13, 2026Updated 4 months ago
- SIEM Cheat Sheet☆83Aug 15, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Listing of YARA rules I wrote for Live and Retro hunts. Includes Jupyter infostealer, suspicious powershell, dll hijacking, vbs downloade…☆16Jun 26, 2026Updated last month
- KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.☆24Nov 7, 2024Updated last year
- PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.☆37Jul 11, 2023Updated 3 years ago
- Thor Artifacts for Velociraptor☆19Dec 2, 2025Updated 7 months ago
- a database that collects data related to APTs from existing public sources through a semi automatic methodology and produces an exhaustiv…☆21Nov 22, 2022Updated 3 years ago
- Threat Detection System using Hybrid (Machine Learning + Lexical Analysis) learning Approach.☆11May 30, 2017Updated 9 years ago
- KQL Sentinel and Defender Detection and Hunting Queries.☆16Jul 8, 2026Updated 2 weeks ago
- Rules Shared by the Community from 100 Days of YARA 2023 -☆19Apr 10, 2023Updated 3 years ago
- ☆26Aug 8, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- All in one - Malware + Analysis by Cylance☆11Nov 23, 2018Updated 7 years ago
- Splunk Queries for SOC Analyst☆16Jan 25, 2024Updated 2 years ago
- A heuristic, python-based detector for fast-flux botnets.☆13Feb 24, 2012Updated 14 years ago
- Evolutionary decision trees☆11Jun 16, 2025Updated last year
- 📨 Quick tool to finds and extract email addresses from a body of text☆12Apr 15, 2023Updated 3 years ago
- Implement a VAE to learn a reduced state space representation from the NSL-KDD dataset, capturing essential features of normal network t…☆14Feb 15, 2024Updated 2 years ago
- Splunk TA for sending completion requests to ChatGPT☆27Jun 12, 2026Updated last month
- A collection of companies that disclose adversary TTPs after they have been breached☆305Jun 7, 2026Updated last month
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆108Mar 12, 2026Updated 4 months ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Hunt the windows Registry automatically using VQL☆18May 4, 2026Updated 2 months ago
- Legacy Sigma Tools (sigmac etc.)☆17May 7, 2023Updated 3 years ago
- PowerShell Memory Pulling script☆19Mar 24, 2015Updated 11 years ago
- Roota is a public-domain language of threat detection and response that combines native queries from a SIEM, EDR, XDR, or Data Lake with …☆139Jul 19, 2024Updated 2 years ago
- Digital Forensics Artifacts Knowledge Base☆90May 16, 2026Updated 2 months ago
- Threat Hunting Malware Infrastructure☆11Dec 3, 2023Updated 2 years ago
- A Microsoft Windows service to provide telemetry on Windows executable memory page changes to facilitate threat detection☆33Oct 7, 2020Updated 5 years ago
- Red Team tool for exfiltrating files from a target's Google Drive that you have access to, via Google's API.☆60Sep 2, 2021Updated 4 years ago
- Exporting MISP event attributes to yara rules usable with Thor apt scanner☆25Mar 27, 2017Updated 9 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Alternative password shadowing scheme☆10Updated this week
- ☆11Feb 9, 2023Updated 3 years ago
- Threat Feeds, Threat lists, and regular lists of known IP ranges and domains. It updates every 4 hours.☆16May 21, 2021Updated 5 years ago
- Analyse metabolic stability predictions using SHapley Additive exPlanations.☆11Jul 26, 2023Updated 3 years ago
- ☆23Mar 12, 2025Updated last year
- Import Mitre Att&ck into Neo4j database☆41Mar 5, 2026Updated 4 months ago
- Git for me to put all my forensics stuff☆23Sep 2, 2025Updated 10 months ago