817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0
Threat Hunting GitHub Repositories
Explore popular GitHub repositories tagged “threat-hunting”.
Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.
Trending Repositories
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
Sysmon configuration file template with default high-quality event tracing
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
IntelOwl: manage your Threat Intelligence at scale
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
A curated list of awesome YARA rules, tools, and people.
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
The Hunting ELK
Rapidly Search and Hunt through Windows Forensic Artefacts
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
A repository of sysmon configuration modules
Interesting APT Report Collection And Some Special IOCs
YARA signature and IOC database for my scanners and tools
No repository description provided.
Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.
Windows Events Attack Samples
Your Everyday Threat Intelligence
Awesome Security lists for SOC/CERT/CTI
A curated knowledge base to build, run and mature a SOC (including CSIRT).
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
Indicators of Compromise from Amnesty International's cyber investigations
Utilities for Sysmon
A Suricata based NDR distribution
A resource containing all the tools each ransomware gangs uses
APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity