Linux Persistence Detection, Hunting and Artifact Collection script
☆24Jul 20, 2026Updated 2 weeks ago
Alternatives and similar repositories for persisthunt
Users that are interested in persisthunt are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A small PoC for bpfdoor malware technique☆23Feb 2, 2024Updated 2 years ago
- This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles …☆29Jul 18, 2026Updated 2 weeks ago
- Track incidents, map attack paths, collaborate in real time, and generate AI-powered reports — all in one place.☆21May 13, 2026Updated 2 months ago
- AI-powered malware traffic analysis and network forensics via the Model Context Protocol☆18May 27, 2026Updated 2 months ago
- AI-powered SOC for OT/ICS networks — 6 autonomous agents, MITRE ATT&CK mapping, Suricata/Zeek ingestion, human-in-the-loop response, 330+…☆31Jul 13, 2026Updated 3 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- A Compiler from Sigma rules to VQL☆19May 18, 2026Updated 2 months ago
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆54Jul 21, 2026Updated last week
- Collection of my own detection rules☆20Jan 6, 2026Updated 6 months ago
- An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation an…☆27Updated this week
- Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups …☆48Updated this week
- Indicators of compromise from to analysis and research by Nextron Threat Research team☆12Jun 2, 2026Updated 2 months ago
- Adversary Simulation Framework☆41Aug 19, 2025Updated 11 months ago
- Automated YARA rule generation from the Cert Central compromised certificate database.☆15Updated this week
- First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extract…☆30May 21, 2026Updated 2 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆154Updated this week
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆32Feb 10, 2026Updated 5 months ago
- Endpoint-State-Policy is a policy-as-data framework for defining, evaluating, and enforcing security requirements across endpoints and cl…☆18May 26, 2026Updated 2 months ago
- Scapy hands-on at #GreHack17☆17Nov 14, 2017Updated 8 years ago
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Jul 28, 2026Updated last week
- HoneyWire: The Open-Source, Unlimited Deception Platform. Turn any Linux machine into an enterprise-grade canary in 60 seconds.☆98Jul 19, 2026Updated 2 weeks ago
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information i…☆17Apr 13, 2026Updated 3 months ago
- C# Desktop GUI application that either performs YARA scan locally or prepares the scan in Active Directory domain environment with a few …☆36Dec 1, 2021Updated 4 years ago
- Tools for Incident Response and Malware Analysis☆11Feb 9, 2025Updated last year
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Browser extension blocking scam and phishing pages https://chromewebstore.google.com/detail/nehboro/ljgklnaofelbcnegjniagpmjknkmaiom☆15Apr 22, 2026Updated 3 months ago
- Case_Notes.py is a cross-platform (Windows, macOS, & Linux) python script to help make the documentation process easier.☆26Jun 24, 2023Updated 3 years ago
- From Chaos to Clarity. Turning Raw Windows Logs into Executive Insights. Looking for Indicators of Compromise.☆48Oct 20, 2025Updated 9 months ago
- ☆15Nov 25, 2021Updated 4 years ago
- Links to malware-related YARA rules☆15Sep 29, 2022Updated 3 years ago
- Sigma detection rules for AI agent security monitoring☆15Updated this week
- ☆20Jul 5, 2026Updated 3 weeks ago
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆130Dec 28, 2025Updated 7 months ago
- MalwareScan is a lightweight and fast malware scanner written in Python. It supports both Windows and Linux platforms and provides an ope…☆13Jun 2, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- surface-watch monitors the authorized external attack surface of an organization over time☆56May 11, 2026Updated 2 months ago
- A Payload Analysis Framework☆123Oct 9, 2025Updated 9 months ago
- Run TTPs, with AI!☆140Feb 23, 2026Updated 5 months ago
- Sysmon Config Pusher - Modernized☆45Jan 7, 2026Updated 6 months ago
- Helping defenders learn and validate npm supply-chain detections with safe atomic tests.☆34Oct 30, 2025Updated 9 months ago
- WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing and configuring Windows event log settings. Windows event logs are a vital s…☆114Updated this week
- ☆23Dec 15, 2022Updated 3 years ago