Linux Persistence Detection, Hunting and Artifact Collection script
☆25Jul 20, 2026Updated last month
Alternatives and similar repositories for persisthunt
Users that are interested in persisthunt are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A small PoC for bpfdoor malware technique☆23Feb 2, 2024Updated 2 years ago
- This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles …☆29Updated this week
- Track incidents, map attack paths, collaborate in real time, and generate AI-powered reports — all in one place.☆21May 13, 2026Updated 3 months ago
- AI-powered malware traffic analysis and network forensics via the Model Context Protocol☆18May 27, 2026Updated 2 months ago
- A Compiler from Sigma rules to VQL☆20May 18, 2026Updated 3 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆56Aug 11, 2026Updated last week
- AI-powered SOC for OT/ICS networks — 6 autonomous agents, MITRE ATT&CK mapping, Suricata/Zeek ingestion, human-in-the-loop response, 330+…☆33Aug 6, 2026Updated 2 weeks ago
- Collection of my own detection rules☆20Jan 6, 2026Updated 7 months ago
- An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation an…☆29Aug 10, 2026Updated 2 weeks ago
- Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups …☆48Updated this week
- Indicators of compromise from to analysis and research by Nextron Threat Research team☆16Aug 11, 2026Updated last week
- Adversary Simulation Framework☆41Aug 19, 2025Updated last year
- Automated YARA rule generation from the Cert Central compromised certificate database.☆15Updated this week
- First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extract…☆31May 21, 2026Updated 3 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆154Jul 28, 2026Updated 3 weeks ago
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆34Feb 10, 2026Updated 6 months ago
- HoneyWire: The Open-Source, Unlimited Deception Platform. Turn any Linux machine into an enterprise-grade canary in 60 seconds.☆102Jul 19, 2026Updated last month
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Jul 28, 2026Updated 3 weeks ago
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information i…☆17Apr 13, 2026Updated 4 months ago
- C# Desktop GUI application that either performs YARA scan locally or prepares the scan in Active Directory domain environment with a few …☆36Dec 1, 2021Updated 4 years ago
- Tools for Incident Response and Malware Analysis☆11Feb 9, 2025Updated last year
- Browser extension blocking scam and phishing pages https://chromewebstore.google.com/detail/nehboro/ljgklnaofelbcnegjniagpmjknkmaiom☆16Apr 22, 2026Updated 4 months ago
- Case_Notes.py is a cross-platform (Windows, macOS, & Linux) python script to help make the documentation process easier.☆26Jun 24, 2023Updated 3 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- From Chaos to Clarity. Turning Raw Windows Logs into Executive Insights. Looking for Indicators of Compromise.☆48Oct 20, 2025Updated 10 months ago
- ☆15Nov 25, 2021Updated 4 years ago
- Links to malware-related YARA rules☆15Sep 29, 2022Updated 3 years ago
- Sigma detection rules for AI agent security monitoring☆16Jul 28, 2026Updated 3 weeks ago
- ☆20Jul 5, 2026Updated last month
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆131Dec 28, 2025Updated 7 months ago
- MalwareScan is a lightweight and fast malware scanner written in Python. It supports both Windows and Linux platforms and provides an ope…☆13Jun 2, 2025Updated last year
- surface-watch monitors the authorized external attack surface of an organization over time☆55May 11, 2026Updated 3 months ago
- A Payload Analysis Framework☆123Oct 9, 2025Updated 10 months ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Run TTPs, with AI!☆140Feb 23, 2026Updated 6 months ago
- Sysmon Config Pusher - Modernized☆46Jan 7, 2026Updated 7 months ago
- WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing and configuring Windows event log settings. Windows event logs are a vital s…☆118Aug 1, 2026Updated 3 weeks ago
- Helping defenders learn and validate npm supply-chain detections with safe atomic tests.☆34Oct 30, 2025Updated 9 months ago
- ☆23Dec 15, 2022Updated 3 years ago
- A unified investigation cockpit built for CSIRT / SOC / DFIR teams. Ingest, correlate and visualise any forensic source in a real-time in…☆40Aug 13, 2026Updated last week
- ☆21Dec 29, 2024Updated last year