GitStar
GitHub TrendingTopicsLanguages
/

Threat Hunting GitHub Repositories

Explore popular GitHub repositories tagged “threat-hunting”.

Compare stars, forks, and programming language using the same GitStar view as GitHub Trending.

RepositoriesGitHub topic
Ranked by:Stars

Trending Repositories

mukul975/Anthropic-Cybersecurity-Skills

817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

Python28,7953,470
OISF/suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.

C6,5541,756
MISP/MISP

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

PHP6,4791,626
elceef/dnstwist

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

Python5,727853
SwiftOnSecurity/sysmon-config

Sysmon configuration file template with default high-quality event tracing

5,6241,864
Security-Onion-Solutions/securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

Shell4,833669
0x4D31/awesome-threat-detection

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

4,701757
intelowlproject/IntelOwl

IntelOwl: manage your Threat Intelligence at scale

Python4,673658
OTRF/ThreatHunter-Playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

Python4,634858
pedramamini/awesome-yara

A curated list of awesome YARA rules, tools, and people.

4,256552
alexandreborges/malwoverview

Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.

Python4,067555
Cyb3rWard0g/HELK

The Hunting ELK

Jupyter Notebook3,930689
WithSecureLabs/chainsaw

Rapidly Search and Hunt through Windows Forensic Artefacts

Rust3,633300
Yamato-Security/hayabusa

Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.

Rust3,313290
olafhartong/sysmon-modular

A repository of sysmon configuration modules

PowerShell3,118657
blackorbird/APT_REPORT

Interesting APT Report Collection And Some Special IOCs

Python3,079576
Neo23x0/signature-base

YARA signature and IOC database for my scanners and tools

YARA3,006675
elastic/detection-rules

No repository description provided.

Python2,688693
osintbrazuca/osint-brazuca

Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.

Python2,655357
sbousseaden/EVTX-ATTACK-SAMPLES

Windows Events Attack Samples

HTML2,608438
yeti-platform/yeti

Your Everyday Threat Intelligence

Python2,016320
mthcht/awesome-lists

Awesome Security lists for SOC/CERT/CTI

YARA1,858227
cyb3rxp/awesome-soc

A curated knowledge base to build, run and mature a SOC (including CSIRT).

1,800284
Bert-JanP/Hunting-Queries-Detection-Rules

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

Python1,732327
matanolabs/matano

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Rust1,694122
AmnestyTech/investigations

Indicators of Compromise from Amnesty International's cyber investigations

Python1,692183
nshalabi/SysmonTools

Utilities for Sysmon

TypeScript1,657209
StamusNetworks/Clear-NDR-ISO

A Suricata based NDR distribution

Shell1,591289
BushidoUK/Ransomware-Tool-Matrix

A resource containing all the tools each ransomware gangs uses

1,430155
ahmedkhlief/APT-Hunter

APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

Python1,417246
GitStar

See what the GitStar community is most excited about today.

Trending

GitHub Trending TodayGitHub Trending WeeklyGitHub Trending Monthly

Languages

Browse all languagesTrending PythonTrending JavaScript

Explore

Browse GitHub topicsAI repositoriesDeveloper tools
© 2026 GitStarGitHub Trending source