eSentire / iocs
☆33Updated last week
Alternatives and similar repositories for iocs:
Users that are interested in iocs are comparing it to the libraries listed below
- CarbonBlack EDR detection rules and response actions☆71Updated 7 months ago
- yara detection rules for hunting with the threathunting-keywords project☆116Updated last month
- A specification and style guide for YARA rules☆47Updated last year
- Active C&C Detector☆153Updated last year
- Contains compiled binaries of Volatility☆33Updated 2 months ago
- A running list of Windows sources and the related event ids.☆19Updated last year
- Yara Rules for Modern Malware☆76Updated last year
- Placeholder for my detection repo and misc detection engineering content☆43Updated last year
- Raw data from Threat Intelligence Reports with automatic reports collection and keyword search across thousands of reports☆106Updated this week
- ShellSweeping the evil.☆52Updated 9 months ago
- The home of the SDDLMaker☆14Updated 3 months ago
- A home for detection content developed by the delivr.to team☆67Updated 2 months ago
- Sigma rules to share with the community☆119Updated 2 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆84Updated 2 months ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆51Updated 4 months ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆59Updated 2 years ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆76Updated last year
- ☆41Updated this week
- Sigma detection rules for hunting with the threathunting-keywords project☆55Updated last month
- Slides of my public talks☆55Updated last year
- ☆31Updated this week
- Repo containing various intel-based resources such as threat research, adversary emulation/simulation plan and so on☆81Updated 11 months ago
- Detection Engineering with YARA☆87Updated last year
- ☆68Updated last month
- Full of public notes and Utilities☆98Updated 2 months ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆52Updated last year
- An introduction to detection engineering☆13Updated 3 months ago
- YARA rule analyzer to improve rule quality and performance☆98Updated last week
- custom Python script to perform Yara matching in Cortex XDR☆12Updated 3 years ago
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆15Updated last year