Library of threat hunts to get any user started!
☆51Sep 4, 2020Updated 6 years ago
Alternatives and similar repositories for TheThreatHuntLibrary
Users that are interested in TheThreatHuntLibrary are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Threat Hunt Investigation Methodology and Procedure☆15Jul 11, 2022Updated 4 years ago
- Forensic cheatsheets for use with cheat☆15Dec 2, 2021Updated 4 years ago
- Parser for Sdba memory pool tags☆21Jul 16, 2021Updated 5 years ago
- High-level Threat Intelligence playbooks☆21Mar 6, 2021Updated 5 years ago
- MalwareAnalysis☆12Dec 19, 2020Updated 5 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- A command-line tool for parsing Windows Master File Table ($MFT) and importing the results into Elasticsearch.☆12Jun 3, 2026Updated 3 months ago
- Here are some tools I developed to help analyze malware☆11Nov 8, 2023Updated 2 years ago
- evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.☆159Nov 30, 2021Updated 4 years ago
- Repository for different Windows DFIR related CMDs, PowerShell CMDlets, etc, plus workshops that I did for different conferences or event…☆76Jul 13, 2021Updated 5 years ago
- A repository to share publicly available Velociraptor detection content☆206Updated this week
- Repository with Sample threat hunting notebooks on Security Event Log Data Sources☆70Dec 2, 2022Updated 3 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆43Jul 18, 2022Updated 4 years ago
- A collection of Terraform and Ansible scripts that automatically (and quickly) deploys a small Velociraptor R&D lab.☆22Apr 16, 2021Updated 5 years ago
- PyVelociraptor contains the python bindings for the Velociraptor API.☆23May 5, 2026Updated 4 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- $MFT parser (from live systems or a copy of the $MFT) and raw file copy utility☆38Jul 18, 2024Updated 2 years ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆79Jan 9, 2024Updated 2 years ago
- Binary commandline executable to parse ETL files☆69Jun 7, 2018Updated 8 years ago
- Browser extension blocking scam and phishing pages https://chromewebstore.google.com/detail/nehboro/ljgklnaofelbcnegjniagpmjknkmaiom☆16Apr 22, 2026Updated 4 months ago
- Tools for hunting for threats.☆633Aug 14, 2026Updated 3 weeks ago
- PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.☆37Jul 11, 2023Updated 3 years ago
- ☆22Jan 31, 2023Updated 3 years ago
- Malformed Access Log to CSV - Convert Web Server Access Logs to CSV☆18Sep 3, 2024Updated 2 years ago
- Python script for parsing ESET (NOD32) virlog.dat file.☆16Sep 28, 2017Updated 8 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- ☆12Jan 5, 2021Updated 5 years ago
- Repo that hold write-ups of various research projects I did and/or overall InfoSec things I investigated/researched.☆22Jan 5, 2025Updated last year
- A repo to centralize some of the regular expressions I've found useful over the course of my DFIR career.☆109Mar 12, 2026Updated 5 months ago
- Repository with selected IOCs and YARA rules for threat hunting.☆35Apr 8, 2026Updated 4 months ago
- Hunt for Keywords , Mutex, Windows Event,Registry Keys,Process,Schedule tasks in Windows Machine☆22Dec 8, 2024Updated last year
- Ekoparty's BlueSpace Keynote November 2021. Shoutout to @plugxor Muchas Gracias!!!☆13Jun 5, 2023Updated 3 years ago
- The Threat Hunting In Rapid Iterations (THIRI) Jupyter notebook is designed as a research aide to let you rapidly prototype threat huntin…☆154Apr 25, 2022Updated 4 years ago
- ☆33Oct 25, 2021Updated 4 years ago
- Practical Information Sharing between Law Enforcement and CSIRT communities using MISP☆37Sep 18, 2023Updated 2 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ☆33Feb 26, 2022Updated 4 years ago
- Threat Box Assessment Tool☆19Mar 5, 2026Updated 6 months ago
- A simple way of detecting multithreaded exfiltration in Zeek.☆15May 1, 2025Updated last year
- A repository of DFIR-related Mind Maps geared towards the visual learners!☆552Sep 2, 2022Updated 4 years ago
- A collaboration effort by the DFIR community to provide definitions (sometimes multiple) for common forensic terms!☆27Dec 1, 2022Updated 3 years ago
- ☆16Jan 31, 2015Updated 11 years ago
- Python bindings for https://github.com/omerbenamram/mft☆25Dec 23, 2025Updated 8 months ago