NRD-db
Automatically fetches and stores newly registered domains in a Redis database.
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
Automatically fetches and stores newly registered domains in a Redis database.
(source code) - The ATT&CK Navigator is designed to provide basic navigation and annotation of ATT&CK matrices, something that people are already doing today in tools like Excel.
A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities.
Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices.
PowerShell Obfuscation Detection Framework.
A PowerShell script to interact with the MITRE ATT&CK Framework via its own API.
A reference implementation provides a framework for collecting events (process creation, network connections, Window Event Logs, etc.) from a client machine and performing CAR analytics to detect potential adversary activity.
An analytical framework for network traffic and behavioral analytics.
A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment.
Lateral movement and threat hunting tool for Windows environments built on Django comes Docker ready.
Bro integration with osquery
A module for osquery to load Bro logs into tables
A PowerShell Module for Hunt Teaming via Windows Event Logs
An online translator for SIEM saved searches, filters, queries, API requests, correlation and Sigma rules
A suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows
An open-source crisis management orchestration framework
Event Query Language
The Event Query Language Analytics Library (eqllib) is a library of event based analytics, written in EQL to detect adversary behaviors identified in MITRE ATT&CK™.
(Bro/Zeek ATT&CK-based Analytics and Reporting) - A set of Zeek scripts to detect ATT&CK techniques
An open-source Linux distribution for threat hunting, security monitoring, and log management. It includes ELK, Snort, Suricata, Zeek, Wazuh, Sguil, and many other security tools
A quick & cheap AWS CloudTrail Monitoring with Event Query Language (EQL)
Serverless, real-time & retroactive malware detection
Scans all running processes, recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
A repository of Azure Sentinel alerts and hunting queries leveraging sysmon and the MITRE ATT&CK framework
A desktop application to efficiently search large packet captures and Zeek logs
An open-source tool to identify capabilities in executable files.
A fast Certificate Transparency Log regex domain lookup tool.
A fast domain typosquatting detection tool.
An Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale.
The pattern matching swiss knife
Splunk-curated detection content that can easily be used accross many SIEMs (see Uncoder Rule Converter.)
Threat intelligence dissemination layer to connect security tools through a distributed publish/subscribe message broker.
A network telemetry engine for data-driven security investigations.
An open source tool to convert Zeek logs to Elastic/OpenSearch. You can also output pure JSON from Zeek's TSV logs!
A standard for reducing log volume without sacrificing analytical capability.
A powerful and user-friendly browser extension that streamlines investigations for security professionals.
Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark.
A framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event.
A framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch
A serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define
An open source security lake platform (SIEM alternative) for threat hunting, detection and response on AWS. Matano lets you write advanced detections as code (using python) to correlate and alert on threats in realtime.
A general purpose security automation platform.
An open platform for detection, response, and threat hunting in email environments. Sublime lets you write advanced detections as code to alert and remediate threats like phishing in real-time.
A cloud native data pipeline and transformation toolkit for security teams.
(github) - SQL powered operating system instrumentation, monitoring, and analytics
A flexible control server for osquery fleets
An endpoint monitoring agent that provides host activity to Zeek
Endpoint visibility and collection tool
A tool for deep Linux system visibility, with native support for containers. Think about sysdig as strace + tcpdump + htop + iftop + lsof + ...awesome sauce
An alternative to the Linux auditd daemon
A Windows system service and device driver that monitors and logs system activity to the Windows event log
A security monitoring tool. It depends on SysinternalsEBPF.
Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
Sysmon configuration file template with default high-quality event tracing.
A repository of sysmon configuration modules. It also includes a mapping of Sysmon configurations to MITRE ATT&CK techniques.
Linux auditd ruleset that produces telemetry required for threat detection use cases.
A repository for using osquery for incident detection and response.
(formerly Bro) - A network security monitoring tool
A web-based network traffic monitoring tool
A network threat detection engine
A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring
A framework for secure and scalable network traffic analysis
) - A large scale and open source full packet capture and search tool
A full-packet-capture tool
A method for profiling SSL/TLS Clients and Servers
Profiling Method for SSH Clients and Servers
Zeek Remote desktop fingerprinting script based on FATT (Fingerprint All The Things)
A pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic
A TLS fingerprinting method
Network fingerprinting and packet metadata capture
A framework for identifying products, services, operating systems, and hardware by matching fingerprints against data returned from various network probes
Fingerprinting HTTP requests
An active Transport Layer Security (TLS) server fingerprinting tool.
An open platform for detection, response, and threat hunting in email environments. Sublime lets you write advanced detections as code to alert and remediate threats like phishing in real-time.
and Analytic stories
Elastic's detection rules written natively for the Elastic SIEM. Can easily be converted for use by other SIEMs using Uncoder.
The Cyber Analytics Repository is a knowledge base of analytics developed by MITRE based on the Adversary Tactics, Techniques, and Common Knowledge (ATT&CK™) adversary model.
YARA rules, tools, and people.
Collection of YARA-L 2.0 sample rules for the Chronicle Detection API.
Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud.
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
Email attack detection, response, and hunting rules.
Pre-recorded security events generated by simulated adversarial techniques in the form of JavaScript Object Notation (JSON) files. The data is categorized by platforms, adversary groups, tactics and techniques defined by the Mitre ATT&CK Framework.
(github repo) - Samples of security related data.
(paper) - The EMBER dataset is a collection of features from PE files that serve as a benchmark dataset for researchers
Canadian Institute for Cybersecurity datasets
A list of public packet capture repositories, which are freely available on the Internet.
A repo of PCAP samples for different ATT&CK techniques.
A repo of Windows event samples (EVTX) associated with ATT&CK techniques (EVTX-ATT&CK Sheet).
A repository of curated datasets from various attacks.
A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.
A great collection of hunts and threat hunting resources.
A collection of resources for threat hunters.
Lists of sources and utilities to hunt, detect and prevent evildoers.
Deception based detection techniques mapped to the MITRE’s ATT&CK framework.
Building a real-time threat detection capability with Tanium that focuses on documented adversarial techniques.
Large-Scale Host and Network Monitoring Using Open-Source Software
Collection of various information focused on malware persistence: detection (techniques), response, pitfalls and the log collection (tools).
(PDF)
YARA rules, tools, and people.
A two-part blog series that outlines a new methodology to extend ATT&CK’s current data sources.
A blog that describes how to align MITRE ATT&CK-based detection content with data sources.
A well experienced detection engineer describes in detail his observations, challenges, and recommendations for building an effective threat detection program.
tweets by Chris Sanders
A video series focused on malware execution and investigations using Elastic Security.
A curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target.
A framework for developing alerting and detection strategies.
The Hunting Maturity Model describes five levels of organizational hunting capability, ranging from HMM0 (the least capability) to HMM4 (the most).
The relationship between the types of indicators you might use to detect an adversary's activities and how much pain it will cause them when you are able to deny those indicators to them.
A model for threat hunting.
It is part of the Intelligence Driven Defense® model for identification and prevention of cyber intrusions activity. The model identifies what the adversaries must complete in order to achieve their objective.
The Detection Maturity Level (DML) model is a capability maturity model for referencing ones maturity in detecting cyber attacks.
(Open Source Security Events Metadata) - A community-led project that focuses on the documentation and standardization of security event logs from diverse data sources and operating systems.
A framework for creating schemas and it also delivers a cybersecurity event schema built with the framework (schema browser).
A framework for planning and discussing adversary engagement operations that empowers you to engage your adversaries and achieve your cybersecurity goals.
A business-centric approach for planning and defining threat detection use cases.
Multiple cheatsheets outlined recommendations for Windows Event logging at various levels of granularity.
A collection of Windows hunting queries
Advanced osquery functionality, File integrity monitoring, process auditing, and more.
Using DNS to Expose and Thwart Attacks
Blue Team Tactics
(source code: mod_sslhaf
a DB of JA3 fingerprints
collected from the University of Colorado Boulder campus network
Examples of using IPython, Pandas, and Scikit Learn to get the most out of your security data.
A library for InfoSec investigation and hunting in Jupyter Notebooks.
by SpecterOps
by Andy Greenberg - True stories from the dark side of the Internet.
by Patrick Gray
by Zack 'techy' Allen
A weekly roundup of digital forensics and incident response news.
An annual conference for the osquery open-source community (querycon.io)
courses by Chris Sanders; Investigation theory, Practical threat hunting, Detection engineering with Sigma, etc.
(BTL1 and BTL2 certificates)
Hands-On SOC Analyst Training
While not directly related to threat detection, the website features training modules on general security and offensive topics that can be beneficial for junior SOC analysts.
Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices.
Hands-on workshops and challenges to practice threat hunting using the BOTS and other datasets.
A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities.
A detection lab created with Terraform and Ansible in Azure.
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk.
Twitter accounts that tweet about threat detection, hunting and DFIR.
An automated adversary emulation system that performs post-compromise adversarial behavior within Windows Enterprise networks.
A Windows Batch script that uses a set of tools and output files to make a system look as if it was compromised.
Small and highly portable detection tests mapped to the Mitre ATT&CK Framework.
flightsim is a lightweight utility used to generate malicious network traffic and help security teams to evaluate security controls and network visibility.
A security preparedness tool to do adversarial simulation.
RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK.
Payload Generation Framework.
Payload Generation for Adversary Simulations.
A modular, menu-driven, cross-platform tool for building repeatable, time-delayed, distributed security events.
(website) - A PowerShell and Python post-exploitation agent.
A PowerShell Post-Exploitation Framework.
A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment.
An open source Breach and Attack Simulation (BAS) tool that assesses the resiliency of private and public cloud environments to post-breach attacks and lateral movement.
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk.
A list of awesome red teaming resources
Wiki to collect Red Team infrastructure hardening resources.
A free course on red team operations and adversary simulations.
Building a real-time threat detection capability with Tanium that focuses on documented adversarial techniques.
A collection of open source and commercial tools that aid in red team operations.
(Google Sheets)
An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
lissy93/awesome-privacy
🦄 A curated list of privacy & security-focused software and services
vavkamil/awesome-bugbounty-tools
A curated list of various bug bounty tools
ashishb/android-security-awesome
A collection of android security related resources
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
qazbnm456/awesome-web-security
🐶 A curated list of Web Security materials and resources.