ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed to inform threat hunt planning. It provides a security detection repository of validated queries and hypotheses, alongside an adversary tradecraft guide that details system behaviors and data sources associated with attacker techniques. The project focuses on the development of hunt blueprints and the standardization of detection logic. It integrates the MITRE ATT&CK framework to map detections and hypotheses to adversary tactics and techniques, ensuring coverage analysis is st
ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to standardize the security detection lifecycle. It functions as a community-driven repository for adversary tradecraft and detection logic, using interactive notebooks to combine technical documentation with executable analytics. The project provides a validation suite for testing security hypotheses against pre-recorded telemetry datasets. This ensures that detection logic is verified in local or cloud environments before being deployed to production. The framework covers security detec
Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa
SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati
ThreatHunter-Playbook थ्रेट हंटिंग प्लेबुक्स, डिटेक्शन इंजीनियरिंग वर्कफ़्लो और एडवर्सरी ट्रेडक्राफ्ट मॉडलिंग को मैनेज करने के लिए एक संरचित फ्रेमवर्क है। यह सुरक्षा निगरानी परिकल्पनाओं को विकसित करने के लिए व्यवहार संबंधी पैटर्न और डिटेक्शन नियमों को टैक्टिकल समूहों में व्यवस्थित करने के लिए एक सिस्टम प्रदान करता है।
cyb3rward0g/threathunter-playbook की मुख्य विशेषताएं हैं: Threat Hunting Workflows, Notebook Analytics, Security Hunt Lifecycle Planning, Security Analysis Notebooks, Detection Logic Development, Security Framework Mappings, Automated Hunting, Interactive Threat Hunt Notebooks।
cyb3rward0g/threathunter-playbook के ओपन-सोर्स विकल्पों में शामिल हैं: vvard0g/threathunter-playbook — ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed… otrf/threathunter-playbook — ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to… withsecurelabs/chainsaw — Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It… smicallef/spiderfoot — SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the… neo23x0/loki — Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a… security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It…