Linux Persistence Detection, Hunting and Artifact Collection script
☆25Jul 20, 2026Updated last month
Alternatives and similar repositories for persisthunt
Users that are interested in persisthunt are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles …☆30Updated this week
- AI-powered malware traffic analysis and network forensics via the Model Context Protocol☆18May 27, 2026Updated 3 months ago
- A Compiler from Sigma rules to VQL☆20May 18, 2026Updated 3 months ago
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆56Sep 6, 2026Updated last week
- AI-powered SOC for OT/ICS networks — 6 autonomous agents, MITRE ATT&CK mapping, Suricata/Zeek ingestion, human-in-the-loop response, 330+…☆34Aug 6, 2026Updated last month
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Collection of my own detection rules☆20Jan 6, 2026Updated 8 months ago
- An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation an…☆29Updated this week
- Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups …☆48Updated this week
- Indicators of compromise from to analysis and research by Nextron Threat Research team☆17Updated this week
- Adversary Simulation Framework☆41Aug 19, 2025Updated last year
- Automated YARA rule generation from the Cert Central compromised certificate database.☆15Updated this week
- First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extract…☆31May 21, 2026Updated 3 months ago
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆154Jul 28, 2026Updated last month
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆34Feb 10, 2026Updated 7 months ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Endpoint-State-Policy is a policy-as-data framework for defining, evaluating, and enforcing security requirements across endpoints and cl…☆18Updated this week
- HoneyWire: The Open-Source, Unlimited Deception Platform. Turn any Linux machine into an enterprise-grade canary in 60 seconds.☆108Aug 28, 2026Updated 2 weeks ago
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Jul 28, 2026Updated last month
- JSHawk is a powerful, context-aware JavaScript security scanner that hunts for exposed credentials, API keys, and sensitive information i…☆17Apr 13, 2026Updated 5 months ago
- C# Desktop GUI application that either performs YARA scan locally or prepares the scan in Active Directory domain environment with a few …☆37Dec 1, 2021Updated 4 years ago
- Tools for Incident Response and Malware Analysis☆11Feb 9, 2025Updated last year
- Browser extension blocking scam and phishing pages https://chromewebstore.google.com/detail/nehboro/ljgklnaofelbcnegjniagpmjknkmaiom☆16Apr 22, 2026Updated 4 months ago
- Case_Notes.py is a cross-platform (Windows, macOS, & Linux) python script to help make the documentation process easier.☆26Jun 24, 2023Updated 3 years ago
- From Chaos to Clarity. Turning Raw Windows Logs into Executive Insights. Looking for Indicators of Compromise.☆48Oct 20, 2025Updated 10 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- ☆15Nov 25, 2021Updated 4 years ago
- Links to malware-related YARA rules☆15Sep 29, 2022Updated 3 years ago
- Sigma detection rules for AI agent security monitoring☆16Jul 28, 2026Updated last month
- ☆20Jul 5, 2026Updated 2 months ago
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆131Dec 28, 2025Updated 8 months ago
- MalwareScan is a lightweight and fast malware scanner written in Python. It supports both Windows and Linux platforms and provides an ope…☆13Jun 2, 2025Updated last year
- surface-watch monitors the authorized external attack surface of an organization over time☆55May 11, 2026Updated 4 months ago
- A Payload Analysis Framework☆124Oct 9, 2025Updated 11 months ago
- Run TTPs, with AI!☆142Feb 23, 2026Updated 6 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Sysmon Config Pusher - Modernized☆46Jan 7, 2026Updated 8 months ago
- WELA (Windows Event Log Analyzer, ゑ羅) is a tool for auditing and configuring Windows event log settings. Windows event logs are a vital s…☆120Sep 3, 2026Updated last week
- Helping defenders learn and validate npm supply-chain detections with safe atomic tests.☆35Oct 30, 2025Updated 10 months ago
- ☆23Dec 15, 2022Updated 3 years ago
- A unified investigation cockpit built for CSIRT / SOC / DFIR teams. Ingest, correlate and visualise any forensic source in a real-time in…☆42Updated this week
- ☆21Dec 29, 2024Updated last year
- HackMap — a local pentest mapping tool with real-time command execution, persistent history per target, visual attack paths, and one-clic…☆50Aug 3, 2026Updated last month