Linux Persistence Detection, Hunting and Artifact Collection script
☆26Jul 20, 2026Updated 2 months ago
Alternatives and similar repositories for persisthunt
Users that are interested in persisthunt are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Proof of concept exploit for Python Security Consideration "logging: Logging configuration uses eval()"☆14Jun 8, 2022Updated 4 years ago
- A Compiler from Sigma rules to VQL☆20May 18, 2026Updated 4 months ago
- This Repository is created after my own research into malicious browser extensions, by brining the work of many others and news articles …☆31Sep 12, 2026Updated 3 weeks ago
- Collection of my own detection rules☆20Jan 6, 2026Updated 8 months ago
- Track incidents, map attack paths, collaborate in real time, and generate AI-powered reports — all in one place.☆21Sep 21, 2026Updated last week
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Indicators of compromise from to analysis and research by Nextron Threat Research team☆19Sep 24, 2026Updated last week
- AI-powered malware traffic analysis and network forensics via the Model Context Protocol☆19May 27, 2026Updated 4 months ago
- Windows EVTX log analysis for DFIR — fast parsing, ATT&CK mapping, IOC extraction, and Sentinel anomaly detection. Normal + Juggernaut Mo…☆59Sep 6, 2026Updated 3 weeks ago
- Automated YARA rule generation from the Cert Central compromised certificate database.☆16Updated this week
- AI-powered SOC for OT/ICS networks — 6 autonomous agents, MITRE ATT&CK mapping, Suricata/Zeek ingestion, human-in-the-loop response, 330+…☆34Aug 6, 2026Updated last month
- Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups …☆49Updated this week
- An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation an…☆29Sep 9, 2026Updated 3 weeks ago
- Endpoint-State-Policy is a policy-as-data framework for defining, evaluating, and enforcing security requirements across endpoints and cl…☆18Sep 10, 2026Updated 3 weeks ago
- Cross-platform incident response toolkit. 28 pre-built use cases in a single zero-install binary: triage, threat hunting, memory forensic…☆157Jul 28, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Tools for Incident Response and Malware Analysis☆11Feb 9, 2025Updated last year
- Adversary Simulation Framework☆40Aug 19, 2025Updated last year
- Case_Notes.py is a cross-platform (Windows, macOS, & Linux) python script to help make the documentation process easier.☆26Jun 24, 2023Updated 3 years ago
- ☆15Nov 25, 2021Updated 4 years ago
- Links to malware-related YARA rules☆15Sep 29, 2022Updated 4 years ago
- Sigma detection rules for AI agent security monitoring☆15Jul 28, 2026Updated 2 months ago
- ☆20Jul 5, 2026Updated 2 months ago
- MalwareScan is a lightweight and fast malware scanner written in Python. It supports both Windows and Linux platforms and provides an ope…☆13Jun 2, 2025Updated last year
- First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extract…☆31May 21, 2026Updated 4 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- HoneyWire: The Open-Source, Unlimited Deception Platform. Turn any Linux machine into an enterprise-grade canary in 60 seconds.☆111Aug 28, 2026Updated last month
- Sysmon Config Pusher - Modernized☆46Jan 7, 2026Updated 8 months ago
- ☆23Dec 15, 2022Updated 3 years ago
- A unified investigation cockpit built for CSIRT / SOC / DFIR teams. Ingest, correlate and visualise any forensic source in a real-time in…☆43Sep 24, 2026Updated last week
- Shattering the 1:10 barrier. A high-velocity alternative to Plaso for the modern IR landscape☆18Jul 6, 2026Updated 2 months ago
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆21Oct 25, 2023Updated 2 years ago
- Random tips and tricks RE: ransomware☆14Aug 17, 2021Updated 5 years ago
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55Sep 15, 2026Updated 2 weeks ago
- MS Graph Commands and Tools for Blue Teamers☆51Feb 4, 2026Updated 7 months ago
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- Threat hunting queries, Sigma rules, and detection engineering research based on MITRE ATT&CK techniques.☆47Updated this week
- Interactive PowerShell framework for testing WMI, COM, LOLBAS, and persistence techniques☆131Dec 28, 2025Updated 9 months ago
- LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footpr…☆20May 25, 2026Updated 4 months ago
- MSIX Building Made Easy for Defenders☆65Aug 25, 2025Updated last year
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆34Feb 10, 2026Updated 7 months ago
- DriverSentinel is a security tool developed in Go that detects malicious and vulnerable drivers on Windows systems by comparing them agai…☆36Jul 28, 2026Updated 2 months ago
- ☆20Oct 23, 2020Updated 5 years ago