Lists of independent cybersecurity blogs covering threat intelligence, purple team, red team, threat hunting, and detection engineering. Most are personal blogs maintained by practitioners who publish original research, tradecraft, and tooling.
☆39May 9, 2026Updated 2 months ago
Alternatives and similar repositories for CyberSec-Blogs
Users that are interested in CyberSec-Blogs are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆32Feb 10, 2026Updated 5 months ago
- Collection of custom implementations about some WinAPI functions☆35Updated this week
- A production-ready, enterprise-grade MDR framework that transforms chaotic security alerts into structured, actionable intelligence.☆23Feb 14, 2026Updated 5 months ago
- Automated YARA rule generation from the Cert Central compromised certificate database.☆15Updated this week
- ThreatCheck - Select any indicator of compromise on any web page - or highlight an entire paragraph from a threat report - and instantly …☆34May 6, 2026Updated 2 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- PowerShell SharePoint extraction + auditing tool for red/blue/purple teams. Enumerates all SharePoint sites/drives a user can access via …☆167Jan 25, 2026Updated 6 months ago
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Updated this week
- Helping defenders learn and validate npm supply-chain detections with safe atomic tests.☆34Oct 30, 2025Updated 9 months ago
- A Bloodhound alternative. BloodBash will ingest the same files bloodhound does but no server is required to use this tool. It's great for…☆341Updated this week
- ☆88Apr 8, 2026Updated 3 months ago
- FireEye iSIGHT Alert Feeder for TheHive, an Open Source and Free Security Incident Response Platform☆16Oct 12, 2018Updated 7 years ago
- Tool to aid in dumping LSASS process remotely☆44Sep 23, 2025Updated 10 months ago
- Atomic test units for BOF execution☆60Apr 26, 2026Updated 3 months ago
- AWSDoor is a red team automation tool designed to simulate advanced attacker behavior in AWS environments☆36Sep 17, 2025Updated 10 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆15Apr 28, 2026Updated 3 months ago
- PowerShell implementation for AD CS☆159Updated this week
- Tool that gathers a customizable set of ETW telemetry and generates user-defined detections☆56Jan 28, 2026Updated 6 months ago
- Stealthy .NET assembly loading using AssemblyNative::LoadFromBuffer☆58Mar 22, 2026Updated 4 months ago
- Gain insights into COM/DCOM implementations that may be vulnerable using an automated approach and make it easy to visualize the data. By…☆164Nov 23, 2025Updated 8 months ago
- a minimal, position-independent C shellcode framework for Windows x64. compiles entirely on Linux☆64Updated this week
- An MCP to expose process monitoring and ETW tracing functionally to AI agents to assist in security work☆78May 6, 2026Updated 2 months ago
- Automatically deploying Mythic C2 in Azure using Terraform☆25Jul 3, 2026Updated last month
- Command and Control Framework using powershell implants☆36Jun 17, 2025Updated last year
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- ☆58Jul 12, 2026Updated 3 weeks ago
- A small guide on Unknown/Orphaned SIDs and some PowerShell tools to help you get rid of them.☆21Apr 16, 2026Updated 3 months ago
- a list of useful feeds☆98May 15, 2026Updated 2 months ago
- DeepProbe - Memory Forensics Framework☆16May 16, 2026Updated 2 months ago
- Novel Windows process injection: assembles existing open handles (process & thread), natural RWX regions, and special user APC (NtQueueAp …☆74Feb 17, 2026Updated 5 months ago
- Automate All Pivoting System Enumeration with this Bash Script☆13Nov 7, 2022Updated 3 years ago
- An offensive postexploitation tool that will give you complete control over the Outlook desktop application and therefore to the emails c…☆166Oct 9, 2024Updated last year
- Tailscale/Headscale C2 profile and agent for Mythic☆25Mar 14, 2026Updated 4 months ago
- Clean Indirect Syscalls with Hook Evasion & Return Address Spoofing.☆100Apr 30, 2026Updated 3 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆18Apr 15, 2024Updated 2 years ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated 11 months ago
- ☆97Updated this week
- goLoL is a Windows host scanner with dual support for LOLBAS binaries and LOLDrivers. It lists LOLBAS techniques runnable at your current…☆66Jun 28, 2026Updated last month
- A sysmon configuration designed for monitoring RMM solutions from the LOLRMM framework on the OS Microsoft Windows. 10/11☆33Feb 17, 2026Updated 5 months ago
- This is a collection of the best resources on Move security for the Sui/Aptos ecosystems.☆19Dec 2, 2025Updated 8 months ago
- A portfolio demonstrating advanced blue and red team skills, including: SSH MFA implementation, Volatility-based memory forensics to dete…☆22Oct 19, 2025Updated 9 months ago