Skip to content
84

Security lists for SOC/DFIR detections

Awesome Security lists for SOC/CERT/CTI

1.9k stars241 forks677 entriesLast push Sep 30, 2026 (today)License MIT

This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.

Threat Hunting:

ThreatHunting keywords Site

ThreatHunting keywords Lists

ThreatHunting Yara rules

Yara rules for Threat Hunting sessions

In 2 lists

ThreatHunting searches

General

Windows Services Searches

User-Agents Searches

DNS Over HTTPS Searches

Suspicious TLDs Searches

HijackLibs Searches

Phishing & DNSTWIST Searches

Browsers extensions Searches

C2 hiding in plain sigh

HTML Smuggling artifacts

PSEXEC & similar tools Searches

Time Slipping detection

Suspicious Named pipes

General

🔥 EricZimmerman Tools 🔥

An updated list of forensic tools created by Eric Zimmerman, an instructor for SANS institute.

In 3 lists

usnjrnl_rewind

dfir-orc

dfir-orc-config

Arsenal Recon Forensic tools

Splunk4DFIR

dfiq

Mind maps

arfifacts List - DFIRArtifactMuseum

arfifacts List - ForensicArtifacts

A free, community-sourced, machine-readable knowledge base of digital forensic artifacts.

In 3 lists

Autopsy

SleuthKit

The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.

In 4 lists

[OS] SIFT Workstation

[OS] Remnux

Linux distribution and docker images for malware reverse engineering and analysis.

In 5 listsDetails

[OS] sof-elk

[OS] tsurugi

heavily customized Linux distribution that designed to support DFIR investigations, malware analysis and OSINT activities. It is based on Ubuntu 20.04(64-bit with a 5.15.12 custom kernel)

In 5 listsDetails

[OS] DEFT

[OS] Flare VM

In 2 lists

PSBits

Simple (relatively) things allowing you to dig a bit deeper than usual.

In 3 lists

ThreatHunting Yara rules

Yara rules for Threat Hunting sessions

In 2 lists

Yara - Forge

capa

detects capabilities in executable files. You run it against a PE, ELF, .NET module, or shellcode file and it tells you what it thinks the program can do.

In 3 lists

Malcontent

[Event parser] evtx

[Event Parser] procmon-parser

[Event Parser] Linux - MasterParser

[EVTX] Hayabusa

Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool created by the Yamato Security group in Japan.

In 3 lists

[EVTX] WELA

Windows Event Log Analyzer aims to be the Swiss Army knife for Windows event logs.

In 2 lists

[EVTX] chainsaw

[EVTX] APTHunter

APT-Hunter is Threat Hunting tool for windows event logs.

In 2 lists

[EVTX / Auditd] Zircolite

A standalone and fast SIGMA-based detection tool for EVTX or JSON.

In 2 lists

werejugo

srum-dump

ADTimeline

PersistenceSniper

Powershell module to hunt for persistence implanted in Windows machines.

In 2 lists

[O365] Logs - Microsoft-Analyzer-Suite

Logon Tracer

Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.

In 5 listsDetails

Timeline Plaso

a Python-based backend engine for the tool log2timeline.

In 2 lists

Timeline TimeSketch

Open source tool for collaborative forensic timeline analysis.

In 5 listsDetails

regripper

OneDrive OCR DB artifact collector exe

OneDrive OCR DB artifact collector python

hollows hunter

Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).

In 4 lists

PE sieve

Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).

In 3 lists

RdpCacheStitcher

RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.

In 3 lists

Searching strings - ripgrep

Better and faster grep. Recursively searches directories while respecting gitignore rules and skipping hidden/binary files.; Flavors: Rust (default), PCRE.

In 10 listsDetails

Searching strings - Recoll

Kape

The tool allows collecting various predefined artifactgs using targets and modules, see KapeFiles which include persistence mechanisms, among others there's a collection of LNK files, scheduled task files and scheduled task listing or a WMI repository auditing module.

In 2 lists

Kape Files

More Kape ressources

VolatileDataCollector

In 2 lists

Velociraptor

Velociraptor is a tool for collecting host based state information using Velocidex Query Language (VQL) queries

In 5 listsDetails

TZ tools

Nirsoft tools

[memory] MemDump

[memory] MemProcFS

An easy and convenient way of accessing physical memory as files a virtual file system.

In 3 lists

[memory] MemProcFS-Analyzer

PowerShell script utilized to simplify the usage of MemProcFS and to optimize your memory analysis workflow.

In 2 lists

[memory] avml

A portable volatile memory acquisition tool for Linux.

In 3 lists

[memory] WinPmem

[memory] Volatility

The volatile memory extraction framework (successor of Volatility)

In 3 lists

[Image Mount] FTK Imager

[Image Mount] OSFMount

allows you to mount local disk image files (bit-for-bit copies of an entire disk or disk partition) in Windows as a physical disk or a logical drive

In 2 lists

[Network] Network Miner

A network forensic tool for PCAP file analysis.

In 2 lists

[Network] Wireshark

Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Wireshark is very similar to tcpdump, but has a graphical front-end, plus some integrated sorting and filtering options.

In 20 listsDetails

[Network] xplico

In 2 lists

[Carving] PhotoRec

[Carving] Bulk Extractor

Computer forensics tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures. Because of ignoring the file system structure, the program distinguishes itself in terms of speed and thoroughness.

In 6 listsDetails

Didier Stevens tools

[memory] Lime

Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, formerly called DMD.

In 4 lists

Windows artifacts

[Guide to the various Windows forensic artifacts]

In 2 lists

[Linux] UAC

UAC (Unix-like Artifacts Collector) is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.

In 2 lists

[Linux] EXT4 / XFS - fjta

Tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), generates timelines, and detects suspicious activities

In 2 lists

lists - aboutdfir.com

Collection of forensic resources for learning and research. Offers lists of certifications, books, blogs, challenges and more

In 2 lists

Monitoring - Osquery

is a SQL powered operating system instrumentation, monitoring, and analytics framework.

In 6 listsDetails

[IR Guide] OpenProject

[OSX Tools] mac_apt

Plugin based forensics framework for quick mac triage that works on live machines, disk images or individual artifact files.

In 4 lists

Browser Chrome Extensions DNS Forensic

General

chainabuse (for malicious owned crypto wallets address)

Report and search crypto scam addresses.

In 3 lists

ABUSE.CH BLACKLISTS

Block Lists

DNS Block List

Phishing Block List

Binary Defense IP Block List

C2IntelFeeds

C2 intelligence feeds for threat hunting.

In 2 lists

Volexity TI

sparkles: :gem:; This repository contains IoCs related to Volexity public threat intelligence blog posts.

In 3 lists

Open Source TI

C2 Tracker

Unit42 IOC

Sekoia IOC

Unit42 Timely IOC

Unit42 Articles IOC

IOCs and supporting data for Palo Alto Networks Unit 42 threat research articles, so indicators can be traced back to their write-up.

In 2 lists

ThreatFOX IOC

Zscaler ThreatLabz IOC

Zscaler ThreatLabz Ransomware notes

experiant.ca

Sophos lab IOC

ESET Research IOC

eyes:; Collection of YARA and Snort rules from IOCs collected by ESET researchers. There's about a dozen YARA Rules to glean from in this repo, search for file extension .yar. This repository is seemingly updated on a roughly monthly interval. New IOCs are often mentioned on the ESET…

In 4 lists

ExecuteMalware IOC

Cisco Talos IOC

IOCs from Cisco Talos.

In 2 lists

Elastic Lab IOC

Blackorbid APT Report IOC

AVAST IOC

Zimperium IOC

HarfangLab IOC

DoctorWeb IOC

BlackLotusLab IOC

prodaft IOC

Pr0xylife DarkGate IOC

Pr0xylife Latrodectus IOC

Pr0xylife WikiLoader IOC

Pr0xylife SSLoad IOC

Pr0xylife Pikabot IOC

Pr0xylife Matanbuchus IOC

Pr0xylife QakBot IOC

Pr0xylife IceID IOC

Pr0xylife Emotet IOC

Pr0xylife BumbleBee IOC

Pr0xylife Gozi IOC

Pr0xylife NanoCore IOC

Pr0xylife NetWire IOC

Pr0xylife AsyncRAT IOC

Pr0xylife Lokibot IOC

Pr0xylife RemcosRAT IOC

Pr0xylife nworm IOC

Pr0xylife AZORult IOC

Pr0xylife NetSupportRAT IOC

Pr0xylife BitRAT IOC

Pr0xylife BazarLoader IOC

Pr0xylife SnakeKeylogger IOC

Pr0xylife njRat IOC

Pr0xylife Vidar IOC

Pr0xylife Warmcookie IOC

Cloud Intel IOC

Phihsing urls - last week feed

SpamHaus drop.txt

SpamHaus drop + ASN

UrlHaus_misp

UrlHaus_misp ASN

UrlHaus

Community-driven repository for real-time malicious URL data, offering actionable threat intelligence to block phishing and malware.

In 2 lists

vx-underground - Great Resource for Samples and Intelligence Reports

PL-CERT based open source MWDB python application holding a malware database containing every APT sample from 2010 and over 7.5M maliciousbinaries.

In 2 lists

Ransomware.live

A monitoring ransomware's victims in near real-time.

In 2 lists

rosti.bin public reports feed

General

More github lists

General

EDR Telemetry

ThreatHunting searches

Awesome-SOC

Awesome SOC analyst

ThreatHunting keywords Lists

Detection Lists

PurpleTeam atomics

A red team attack techniques framework supporting also the MITRE ATT&CK persistence techniques, see e.g. T1044 "File System Permissions Weakness".

In 6 listsDetails

General

Tools used by ransomware groups - @BushidoToken

Tools used by Russian APT

Tools associated with groups (partial)

Techniques - MITRE ATT&CK

Tactics - MITRE ATT&CK

Mitigation - MITRE ATT&CK

ATT&CK matrix navigator

All MITRE data in xlsx format

Tools used by threat actor groups - MITRE ATT&CK

PurpleTeam atomics

A red team attack techniques framework supporting also the MITRE ATT&CK persistence techniques, see e.g. T1044 "File System Permissions Weakness".

In 6 listsDetails

redcanary Threat Detection report

Threat Detection Report (2026) - Analyzes the evolving cybersecurity landscape by examining over one hundred thousand confirmed threats across diverse infrastructure and identity environments. Key findings reveal that identity based attacks surged by 850 percent year over year, now accounting for…

In 2 lists

The-Unified-Kill-Chain

TTP pyramid

Pyramid of pain

Cyber Kill chain

Lockheed Martin's framework that outlines the 7 stages commonly observed in a cyber attack.

In 2 lists

MITRE D3FEND

MITRE CAPEC

MITRE CAR

The Cyber Analytics Repository is a knowledge base of analytics developed by MITRE based on the Adversary Tactics, Techniques, and Common Knowledge (ATT&CK™) adversary model.

In 3 lists

MITRE DeTTECT

MITRE PRE-ATT&CK Techniques

APTMAP

CVE Vuln Database

Dictionary of common names (i.e., CVE Identifiers) for publicly known security vulnerabilities.

In 3 lists

CVE Vuln Framework

REACT framework

🔥ALL TI Reports🔥

🔥ALL TI Reports searches🔥

General

Virustotal

VirusTotal, a subsidiary of Google, is a free online service that analyzes files and URLs enabling the identification of viruses, worms, trojans and other kinds of malicious content detected by antivirus engines and website scanners. At the same time, it may be used as a means to detect false…

In 13 listsDetails

SpamHaus

Lookup Reputation Checker.

In 2 lists

app.spur.us

AbuseIPDB

AbuseIPDB is a project dedicated to helping combat the spread of hackers, spammers, and abusive activity on the internet.

In 5 listsDetails

Telegram BOT hunting

Malwarebazaar

Share malware samples for research purposes.

In 2 lists

emailrep

Email address reputation and risk scoring service.

In 4 listsDetails

dnsdumpster

DNSdumpster.com is a FREE domain research tool that can discover hosts related to a domain. Finding visible hosts from the attackers perspective is an important part of the security assessment process.

In 5 listsDetails

nslookup.io

Find all DNS records for a domain name using this online tool

In 3 lists

cloudfare URL scan

URL scanner by Cloudflare for security analysis.

In 2 lists

proxy IP check - proxycheck.io

reputation IP check criminalip

proxy IP check - iphub.info

shodan

Shodan is a search engine that lets users search for various types of servers connected to the internet using a variety of filters. Some have also described it as a search engine of service banners, which are metadata that the server sends back to the client.

In 12 listsDetails

Onyphe

ONYPHE is an Attack Surface Management & Attack Surface Discovery solution built as a Cyber Defense Search Engine. We scan the entire Internet and Dark Web for exposed assets and crawl the links just like a Web search engine. Our data is searchable with a Web form or directly from our numerous APIs.

In 4 listsDetails

haveibeenpwned

Checks if your credentials (Email address or Password) have been compromised in a data breach. See also Firefox Monitor.

In 8 listsDetails

Censys

Search Engine for every server on the Internet to reduce exposure and improve security

In 4 listsDetails

cybergordon (URL reputation check)

CyberGordon is a threat intelligence search engine. It leverages 30+ sources.

In 2 lists

threatminer

ThreatMiner is a threat intelligence portal designed to enable analysts to research under a single interface.

In 4 listsDetails

urlscan

urlscan.io is a free service to scan and analyse websites. When a URL is submitted to urlscan.io, an automated process will browse to the URL like a regular user and record the activity that this page navigation creates.

In 7 listsDetails

Apptotal (apps and extensions analysis)

urlquery

Free URL Scanner.

In 2 lists

cloudfare scanner

Global Internet traffic, attack, and technology trends and insights

In 3 lists

scamsearch.io

search to find phone, email, profile if is tobe a scammer.

In 3 lists

scamdb.net

Report and Search Online Scams

In 2 lists

urlvoid

Analyzes a website through multiple blacklist engines and online reputation tools to facilitate the detection of fraudulent and malicious websites.

In 3 lists

urldna.io

Unleash website insights! urldna.io analyzes data, monitors brands and exposes security risks

In 4 listsDetails

url checkphish

An online tool that finds registered domain typosquats and analyzes them for suspicious activity.

In 3 lists

ipvoid

IP address reputation and blacklist check.

In 3 lists

mxtoolbox

mxtoolbox mail header

Email headers are present on every email you receive via the Internet and can provide valuable diagnostic information like hop delays, anti-spam results and more. If you need help getting copies of your email headers

In 2 lists

Microsoft TI

In 2 lists

pulsedive

A partially free website research tool. Collects detailed information about IP, whois, ssl, dns, ports, threats reports, geolocation, cookies, metadata (fb app id etc). Make screenshots and many others

In 7 listsDetails

URL Redirect Checker

threatbook

One step ahead of your adversary with high-fidelity, efficient and actionable cyber threat intelligence

In 3 lists

web archive

Explore more than 702 billion web pages saved over time

In 4 listsDetails

McAfee Threat Intelligence Exchange

Kaspersky Security Network

Microsoft Security Intelligence Report

IBM X-Force Exchange

Threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers

In 3 lists

AlienVault OTX

Open Threat Exchange is the neighborhood watch of the global intelligence community. It enables private companies, independent security researchers, and government agencies to openly collaborate and share the latest information about emerging threats, attack methods, and malicious actors,…

In 6 listsDetails

greynoise

Search Exposed Internet assets, Malicious IP's.

In 5 listsDetails

whoxy

url tiny-scan

Free URL inspection online tool: ip, location, desktop/mobile screenshots, number of links, javascript files and stylesheets, technology profile, number of request and bytes transferred and more.

In 4 listsDetails

certificates - crt.sh

Enter an Identity (Domain Name, Organization Name, etc), a Certificate Fingerprint (SHA-1 or SHA-256) or a crt.sh ID to search certificate(s) by @crtsh.

In 6 listsDetails

site web-check

Get detailed report about IP or domain: Location SSL Info Headers Domain and host names Whois DNS records Crawl riles Cookies Server Info Redirects Server status TXT Config

In 3 lists

validin.com

Website and API to search current and historical DNS records for free

In 3 lists

Browser Extension CRX checker

.EXE lookup - echotrail

Malware-Traffic-Analysis (PCAP files)

A large collection of malicious PCAP files that can be used to practice packet capture skills.

In 2 lists

redhuntlabs

This Custom Search Tool by @RedHuntLabs Team looks for keywords/strings in following Online IDEs, Paste(s) sites and Code Sharing Platforms.

In 2 lists

whois domaintools

Go beyond ordinary Whois to discover the people or organizations behind a domain name or IP address.

In 6 listsDetails

viewdns

OUI mac address lookup

An online OUI lookup for searching vendors of MAC addresses.

In 2 lists

macvendorlookup

Look up the vendor for a specific MAC Address

In 2 lists

.EXE lookup - xcyclopedia

abuse.ch

ZeuS Tracker / SpyEye Tracker / Palevo Tracker / Feodo Tracker tracks Command&Control servers (hosts) around the world and provides you a domain- and an IP-blocklist.

In 3 lists

waybackmachine

Internet Archive

In 2 lists

dnshistory

In 2 lists

asnlookup

Quickly lookup updated information about specific Autonomous System Number (ASN), Organization, CIDR, or registered IP addresses (IPv4 and IPv6) among other relevant data

In 3 lists

ipinfo.io

The trusted source for IP address data

In 5 listsDetails

fofa.info

Cyberspace search engine for security assessment.

In 4 listsDetails

SecurityTrail

Historical and current WHOIS, historical and current DNS records, similar domains, certificate information and other domain and IP related API and tools.

In 6 listsDetails

ZommEye

ZoomEye is a cyberspace search engine for IPs, domains, internet asset discovery, and exposure analysis of servers, routers, and webcams.

In 2 lists

BlueCoat lookup

Norton lookup

Look up a site, Get our rating

In 2 lists

Fortinet lookup

McAfee lookup

Trellix lookup

Palo Alto lookup

Talos Intelligence lookup

IP and Domain Reputation Center for real-time threat detection

In 3 lists

Checkpoint lookup

Cyren lookup

Forcepoint lookup

TrendMicro lookup

USB & PCI database - DeviceHunt

General

Sandbox Anyrun

In 2 lists

triage

Fully automated solution for high-volume malware analysis using advanced sandboxing technology

In 2 lists

capesandbox

joesandbox

filescan.io

Static malware analysis, VBA/Powershell/VBS/JS Emulation

In 2 lists

Hybrid Analysis

Free malware analysis service for the community that detects and analyzes unknown threats using a unique Hybrid Analysis technology

In 6 listsDetails

Virustotal

VirusTotal, a subsidiary of Google, is a free online service that analyzes files and URLs enabling the identification of viruses, worms, trojans and other kinds of malicious content detected by antivirus engines and website scanners. At the same time, it may be used as a means to detect false…

In 13 listsDetails

threat zone

vmray

kaspersky opentip

Scan files, domains, IP addresses, and URLs for threats, malware, viruses

In 2 lists

speakeasy (kernel and user mode emulation)

DOGGuard

Kaspersky Threat Intelligence Portal

General

CyberChef

collection of more than a hundred online #tools for automating a wide variety of tasks (string coding, text comparison, double-space removal)

In 6 listsDetails

jsoncrack

In 2 lists

Grok debugger

JS deobfuscator

HTML/JS deobfuscator

In 2 lists

PCAP online analyzer

Hash calculator

regex101

Best free and best web-based tester.; Flavors: Java, JavaScript, .NET, PCRE, RE2, Rust, and emulates Python.; Includes regex debugger (PCRE only).

In 6 listsDetails

Javascript Deobfuscator - deobfuscate.relative.im

JSONViewer

TextMechanic

UrlEncode.org

온라인 url 인코더/디코더

In 2 lists

TextFixer

RegExr

[GitHub] - Best open source tester.; Flavors: JavaScript, PCRE.; Languages: 🇺🇸, 🇨🇳 (fork).

In 4 listsDetails

TextUtils

TextCompactor

Pretty Diff

available

In 2 lists

XML Tree

Online XML Formatter and Beautifier

XML Escape Tool

DiffChecker

CSVJSON

HTML Formatter

Text Tool

String Manipulation Tool

unshorten it

In 2 lists

urlunscrambler

longurl

Message Header

mxtoolbox mail header

Email headers are present on every email you receive via the Internet and can provide valuable diagnostic information like hop delays, anti-spam results and more. If you need help getting copies of your email headers

In 2 lists

Email Header Analyzer

Email Header Analysis

Gitlab dashboard from Excel

uncoder

An online translator for SIEM saved searches, filters, queries, API requests, correlation and Sigma rules

In 2 lists

DeHashed

DeHashed helps prevent ATO with our extensive data set & breach notification solution. Match employee and consumer logins against the world’s largest repository of aggregated publicly available assets leaked from third-party breaches. Secure passwords before criminals can abuse stolen information,…

In 5 listsDetails

IT tools

IT Tools - Handy online tools for developers (Open source) (🇬🇧); Featured tools: Token generator, Hash text, Bcrypt

In 5 listsDetails

ChatGPT

ChatGPT is an AI language model designed to understand and generate human-like text, facilitating conversation and assisting with various tasks website

In 8 listsDetails

General

Techniques - MITRE ATT&CK

MITRE Updates

MITRE D3FEND

ATT&CK matrix navigator

MITRE Datasources

Data source objects added to MITRE ATT&CK as part of v10.

In 2 lists

GTFOBIN

LOLBAS

LOTS

Cataloging how cyber attackers abuse legitimate platforms like GitHub or Google Docs to host malware, C2, or exfiltrate data

In 2 lists

LOLRMM

loldrivers

Open-source project that brings together vulnerable, malicious, and known malicious Windows drivers

In 2 lists

LOLC2

LOLESXI

WTFBIN

Catalogue benign applications that exhibit suspicious behavior. These binaries can emit noise and false positives in threat hunting and automated detections

In 2 lists

Sigma

Splunk Rules

and Analytic stories

In 2 lists

Elastic Rules

Elastic's detection rules written natively for the Elastic SIEM. Can easily be converted for use by other SIEMs using Uncoder.

In 3 lists

DFIR-Report Sigma-Rules

JoeSecurity Sigma-Rules

mdecrevoisier Sigma-Rules

P4T12ICK Sigma-Rules

tsale Sigma-Rules

list of detections resources

KQL Hunting Queries

A list of endpoint detections and hunting queries for Microsoft Defender for Endpoint, Defender For Identity, and Defender For Cloud Apps.

In 2 lists

detection engineering resources

Defender Resource

awesome-threat-detection

LOLOLFarm

A collection of resources for thriving off the land.

In 2 lists

General

Adam Chester Blog Feed

ahnlab apt feed

ahnlab cert feed

ahnlab phishing feed

ahnlab trend feed

Akamai blog feed

Any.run malware analysis blog feed

Avast Blog feed

badsectorlabs Last week in security - Redteam

bi-zone blog feed

bitdefender labs feed

binarydefense blog feed

Blackberry blog

Bleepingcomputer Feed

broadcom blog feed

CERT FR Alerts

CERT FR Avis

CERT LV feed

CERT PL feed

CERT SE feed

CERT SI feed

CERT UA feed

CERT-FR

Checkpoint Research feed

CIRT bd feed

CISA news feed

CISA news

Cisco Talos

The threat intelligence organization at the center of the Cisco Security portfolio

In 4 listsDetails

claroty team82 research

In 2 lists

Cloudfare security feed

Clément Notin Feed

crowdstrike counter adversary operations blog

deepinstinct blog

detect.fyi

Detection engineering weekly

A newsletter dedicated to news and how-tos for Detection Engineering.

In 3 lists

DFIR weekly news

A weekly roundup of digital forensics and incident response news.

In 2 lists

DFIR weekly news feed

drweb virus alert feed

eclecticiq threat intel

Elastic security labs blog

elastic security labs blog feed

EricaZelic Blog

forcepoint lab blog

genians threat intel feed

gi7w0rm threat intel feed

Google Project Zero blog feed

Google threat intelligence feed

Google Threat Intelligence

Google Threat analysis feed

Group-IB feed

HackerNews Feed

harfanglab lab feed

hexacorn blog feed

horizon3 Feed

hunt.io blog

huntress blog feed

IC3 CSA feed

Infostealers Hub News Feed

infostealers reports feed

Intrinsec feed

isc sans edu feed

JPCERT feed

JPCERT

krebsonsecurity feed

Investigative reporting on cybercrime, breaches, and threat actors.

In 2 lists

malwarebytes blog feed

malwaretech feed

Mauricio Velazco Blog

mcafee labs feed

Michael Haag Blog

Microsoft security blog feed

Microsoft Incident response ninja hub

Microsoft Threat Intel feed

morphisec threat research

NCC Group research feed

nccgroup research blog security

NCSC news feed

NIST CVEs

NIST cybersecurity insights feed

Offensive Research - DSAS by INJECT

orangecyberdefense Intel

outpost24 research and threat intel feed

proofpoint threat insight

Qualys Threat research feed

redcanary feed

reversinglabs threat research

sans blog

security.com threat intel

securityaffairs apt feed

securityweek feed

securlist apt targeted attacks feed

Sekoia Blog

Sekoia blog feed

SentinelOne labs feed

seqrite techical blog

Simone Kraus blog feed

sophos threat research feed

specterops feed

Splunk Research Blog

Sybersecyrity news feed

Talos feed

tenable Blog

thedfirreport feed

threat connect blog feed

threatlabz zscaler blog

threatpost feed

trendmicro security feed

Trustwave blog feed

Twitter

In 2 lists

Unit42 feed

Unit42 feed

virusbulletin feed

virusbulletin

volexity blog feed

welivesecurity feed

tl;dr sec newsletter

. A weekly distillation of the best security tools, blog posts, and conference talks, covering AppSec, cloud and container security, DevSecOps, and more.

In 3 lists

General

DFIR - 13cubed videos

DFIR - SANS videos

DFIR - MyDFIR

DFIR - DFIRScience

Malware Analysis - jstrosch

Malware Analysis - cyberraiju

Malware Analysis - Botconf

DFIR - AntisyphonTraining

DFIR - BlackPerl

Malware Analysis - malwareanalysisforhedgehogs

DFIR - BlueMonkey4n6

DFIR - binaryzone

Detection Engineering - Splunk - atomicsonafriday

Exploitation - HackerSploit

DFIR - TheTaggartInstitute

Malware Analysis - JohnHammond

Malware Analysis - invokereversing

Exploitation - Defcon Talks

+ https://media.defcon.org/

Exploitation - Alh4zr3d - twitch

Exploitation - Alh4zr3d - youtube

Exploitation - incodenito

Exploitation - dayzerosec

Malware Analysis - MalwareTechBlog

Malware Analysis - radkawar

Exploitation - LiveOverflow

Malware Analysis - neoeno

Malware Analysis - AzakaSekai

CTI - bushidotoken

CTI - @TLP_R3D

Windows Internal - @mrexodia

!!! Exploitation - ippsec

Exploitation - flangvik

Conferences channel - scrtinsomnihack

Conferences channel - OffensiveCon

Conferences channel - BSidesSF

Conferences channel - BSidesTLV

Conferences channel - bsidesbudapest

Conferences channel - SecuritybsidesOrgUk

Conferences channel - bsidescanberra9688

Conferences channel - brucontalks

Conferences channel - DEFCONConference

Conferences channel - Disobey

Conferences channel - hitbsecconf

Conferences channel - SANSOffensiveOperations

Conferences channel - BlackHillsInformationSecurity

Conferences channel - RITSEC

Conferences channel - Preludeorg

Conferences channel - BlackHatOfficialYT

Conferences channel - TROOPERScon

Conferences site - infocon.org

In 3 lists

Conferences site - sectube.tv

Conferences channel - x33conf

General

darknetdiaries

Description: Darknet Diaries explores true stories from the dark side of the Internet. Go behind the hack and hear stories from the "cyber" front lines. Whether you're just curious how hacks happen or are a seasoned Infosec pro, you'll learn something new in an entertaining format.; Host: Jack…

In 4 lists

risky.biz

by Patrick Gray

In 2 lists

DFIR Podcasts

cloud.withgoogle.com

Internet Storm Center sans podcast

Description: Stormcasts are daily 5-10 minute information security threat updates.; Host: Dr. Johannes Ullrich @johullrich; Frequency: Daily; Runtime: Regularly 5 mins

In 2 lists

7 minutes security Podcast

hacking-humans

dayzerosec

CISO series

Detection Engineering - Splunk - atomicsonafriday

NolimitSecu (FR)

HacknSpeak (FR)

Radio CSIRT (FR)

DEV podcasts (FR)

Security Conversations

Monde de la cyber (FR)

General

RedTeam - 🔥 Initial Access Guild 🔥 Discord

RedTeam - 🔥 Red-Team VX community 🔥 Discord

RedTeam - evilsocket Discord

RedTeam - OffSec Discord

Threat Hunting - Threat Hunter community Discord

PurpleTeam - Ipurpleteam Discord

Blueteam Detection engineering - Hunter's Den Discord

Blueteam Detection engineering - Sigma HQ Discord

Blueteam Threat Intel - Malcore Discord

General

OSCP - HTB

OSCP - Course PEN200

OSEP - Course PEN300

HackTheBox

OSINT challenges in CTF format.

In 3 lists

Pentestlab

PentesterLab - Hands on labs to understand and exploit simple and advanced web vulnerabilities.

In 7 listsDetails

Root-Me

Hundreds of challenges are available to train yourself in different and not simulated environments

In 6 listsDetails

TryHackMe

TryHackMe is an online platform that teaches cyber security through short, gamified real-world labs.

In 7 listsDetails

Zenk-Security

OpenSecurityTraining2

General

Practical Forensic Imaging

Practical-Linux-Forensics-Digital-Investigators

TheHitchhikersGuidetoDFIRExperiencesFromBeginnersandExperts - Free

Forensic Artifacts - Microsoft GuideBook - free

Eric Zimmerman Manual Tools - Free

The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory

Detecting Malware and Threats in Windows, Linux, and Mac Memory.

In 2 lists

Applied Incident Response

Steve Anson's book on Incident Response.

In 2 lists

SANS FOR500 / FOR508 book

Blue Team Handbook: Incident Response Edition

Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software

Placing the Suspect Behind the Keyboard: DFIR Investigative Mindset

Crafting the InfoSec Playbook: Security Monitoring and Incident

by Jeff Bollinger, Brandon Enright and Matthew Valites.

In 2 lists

Investigating Windows Systems

Evasive Malware: A Field Guide to Detecting, Analyzing, and Defeating Advanced Threats

Blue Team Handbook: SOC, SIEM, and Threat Hunting

BTFM: Blue Team Field Manual

PTFM: Purple Team Field Manual

+ PTFM: Purple Team Field Manual v2

EDR - Introduction to endpoint security

MITRE - 11 Strategies of a World-Class Cybersecurity Operations Center

Big picture on running a SOC - Modern SOC

SANS 555 book

Windows Internals Books

How Linux Works

Linux Device Drivers

Understanding The Linux Virtual Memory Manager

Linux insides

A book-in-progress about the Linux kernel and its insides.

In 4 lists

Linux Ebpf

Windows Security Internals

Hacking Art Exploitation

Hacker Playbook Practical Penetration Testing

RTFM: Red Team Field Manual

Red Team Development and Operations: A practical guide

RTRM: Red Team Reference Manual

POC||GTFO

Hands Machine Learning

General

DFIR - NTFS deepdive - ntfs.com

lists - aboutdfir.com

Collection of forensic resources for learning and research. Offers lists of certifications, books, blogs, challenges and more

In 2 lists

Forensic Artifacts - Microsoft GuideBook - free

Malware Analysis - unprotect.it - Evasion techniques

Exploitation - hacktricks

Exploitation - PayloadsAllTheThings

An API key is a unique identifier that is used to authenticate requests associated with your project. Some developers might hardcode them or leave it on public shares.

In 12 listsDetails

Exploitation - red-team-note

Exploitation - Red Team Notes

DFIR - JPCERT Tools Analysis

In 2 lists

Exploitation - Red Team TTP

Linux - EBPF docs

Providing technical documentation for eBPF.

In 2 lists

DFIR - Microsoft NinjaHub

DEV - Windows PInvoke signatures

Privacy - VPN privacy guide

Detection - GCP Attack - Defense

Detection - Azure Attack Defense

Detection - Unprotect project

Exploitation - Hacker recipes

Logs - Events IDs and others - eventlog-compendium

Logs - Events IDs - ultimatewindowssecurity

Logs - Event IDs & policies - microsoft

Logs - Event IDs Logon types - microsoft

Logs - Azure SigninLogs Schema

Logs - Azure SigninLogs Risk Detection

Logs - AADSTS Error Codes

Logs - Microsoft Errors Search

Logs - Microsoft Defender Event IDs

Logs - Microsoft Defender for Cloud Alert References

A list of all Azure Security for Cloud Alerts, their descriptions, and associated data sources.

In 2 lists

Logs - Microsoft Defender for Identity Alert References

Logs - Microsoft Defender XDR Schemas

To help with multi-table queries, you can use the advanced hunting schema, which includes tables and columns with event information and details about devices, alerts, identities, and other entity types.

In 2 lists

Logs - Microsoft DNS Debug Event IDs

Logs - Sysmon Event IDs

more cheatsheets

Exploitation - TLS details

In 2 lists

SOC - Email Headers IANA

SOC - DKIM, DMARC, SPF

SOC - Kerberos Protocol explained

SOC - ADSecurity AD Attacks

SOC - Pass the ticket explained

SOC - Kerberoasting explained

SOC - Kerberos Unconstrained Delegation explained

SOC - AS_REP roasting explained

SOC - Golden tickets explained

SOC - Skeleton Key explained

SOC - NTLM Relay explained

In 2 lists

SOC - LLMNR Poisoning explained

SOC - DCsync explained

SOC - DCshadow attack explained

SOC - Interview Questions by LetsDefend

SOC - explain shell command arguments

this site will help you quickly understand terminal commands-lines from articles, manuals, and tutorials

In 6 listsDetails

General

LAB automation - ludus

LAB env - windows - GOAD

LAB automation - warhorse

LAB automation - Azure - BadZure

LAB automation - Azure - AzureGoat

A Damn Vulnerable Azure Infrastructure

In 2 lists

[OS] Flare VM

In 2 lists

SandBox - cuckoo

Cuckoo Sandbox is an automated dynamic malware analysis system.

In 3 lists

SandBox - CAPEv2

eyes:; Rules from various authors bundled with the Config And Payload Extraction Cuckoo Sandbox extension (see next section).

In 3 lists

SandBox - Malice (Virustotal self hosted clone)

Massively scalable malware analysis framework.

In 2 lists

Detection platform - wazuh

Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of monitoring file system changes, system calls and inventory changes.

In 7 listsDetails

Detection platform - securityonion

Detection platform - Splunk

Detection platform - Elastic

Deployment - ansible

Ansible is a radically simple IT automation platform that makes your applications and systems easier to deploy. Avoid writing scripts or custom code to deploy and update your applications — automate in a language that approaches plain English, using SSH, with no agents to install on remote systems.

In 11 listsDetails

SOC - Use Case Factory Automation - DetectIQ

Network Logs - StratosphereLinuxIPS

Network Logs - flare-fakenet-ng

Network Logs - maltrail

A malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails and featuring an reporting and analysis interface.

In 5 listsDetails

Purpleteam - openbas

Honeypot - LLM honeypot galah

Honeypot - canary

Honeypot - Respotter (Responder honeypot)

Honeypot - Certiception (ADCS honeypot)

Honeypot - cowrie

Maldev - Defense Evasion - avred

Maldev - Defense Evasion - gocheck

Reconnaissance - HEDnsExtractor

Detection Agent - Sandfly linux agent

Log Forwarder - openwec (windows event forwarder)

Threat Hunting Platform - deephunter

Windows Logs - JonMon

Windows Logs - Sysmon

LInux Logs - ossec

OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

In 6 listsDetails

Linux Logs - ecapture (SSL/TLS)

Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.

In 3 lists

Linux Logs - tracee

A runtime security and forensics tool for Linux which uses eBPF technology to trace the system and applications at runtime, and analyze collected events to detect suspicious behavioral patterns.

In 5 listsDetails

Linux Logs - auditd

Linux Logs - SysmonForLinux

Linux Logs - kunai

CTI - OpenCTI

Open cyber threat intelligence platform.

In 3 lists

CTI - MISP

Threat intelligence platform including indicators, threat intelligence, malware samples and binaries. Includes support for sharing, generating, and validating YARA signatures.

In 3 lists

Code analysis

IR platform - iris-web

IRIS is a web collaborative platform for incident response analysts allowing to share investigations at a technical level.

In 3 lists

IR platform - rAIdline

IR platform - FIR

Cybersecurity incident management platform designed with agility and speed in mind. It allows for easy creation, tracking, and reporting of cybersecurity incidents and is useful for CSIRTs, CERTs and SOCs alike.

In 5 listsDetails

Challenges - DFIR LABS

Log samples - Splunk Attack range

A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk.

In 2 lists

IT - Remote connections manager - xpipe

Access your entire server infrastructure from your local desktop

In 2 lists

Endpoint Security - Windows Hardening - Harden-Windows-Security

Endpoint Security - Linux Hardening - lynis

Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional..

In 4 lists

Endpoint Security - Linux - apparmor

General

Crontab check

markmap.js.org (markdown to mindmap)

Subnet Calculator

chmod calculator

Calculate the octal numeric or symbolic value for a set of file or folder permissions in #Linux servers. Check the desired boxes or directly enter a valid numeric value to see its value in other format

In 2 lists

Epoch time converter

cyberchef

Chrome Addon for TI checks

temp mail

10 minute mail

Disposable mail for 10 min.

In 2 lists

General

Attack animation creator - aceresponder

See category
94

Awesome-Selfhosted

awesome-selfhosted/awesome-selfhosted

A list of Free Software network services and web applications which can be hosted on your own servers

Fresh★ 323k1312 entriesPushed yesterday
91

Awesome Privacy

lissy93/awesome-privacy

🦄 A curated list of privacy & security-focused software and services

Fresh★ 9.9k459 entriesPushed today
89

Awesome Bug Bounty Tools

vavkamil/awesome-bugbounty-tools

A curated list of various bug bounty tools

Fresh★ 6.3k400 entriesPushed yesterday
88

android-security-awesome

ashishb/android-security-awesome

A collection of android security related resources

Fresh★ 9.7k233 entriesPushed 2 days ago
88

Awesome Hacker Search Engines

edoardottt/awesome-hacker-search-engines

A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more

Fresh★ 11k563 entriesPushed 27 days ago
87

Awesome Web Security

qazbnm456/awesome-web-security

🐶 A curated list of Web Security materials and resources.

Fresh★ 14k368 entriesPushed 15 days ago