awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टMCP सर्वरहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेस
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Cyb3rWard0g avatar

Cyb3rWard0g/ThreatHunter-Playbook

0
View on GitHub↗
4,594 स्टार्स·853 फोर्क्स·Python·MIT·13 व्यूज़

ThreatHunter Playbook

ThreatHunter-Playbook थ्रेट हंटिंग प्लेबुक्स, डिटेक्शन इंजीनियरिंग वर्कफ़्लो और एडवर्सरी ट्रेडक्राफ्ट मॉडलिंग को मैनेज करने के लिए एक संरचित फ्रेमवर्क है। यह सुरक्षा निगरानी परिकल्पनाओं को विकसित करने के लिए व्यवहार संबंधी पैटर्न और डिटेक्शन नियमों को टैक्टिकल समूहों में व्यवस्थित करने के लिए एक सिस्टम प्रदान करता है।

इस प्रोजेक्ट में एक इंटरैक्टिव सुरक्षा नोटबुक एनवायरनमेंट है जो टेलीमेट्री डेटासेट के खिलाफ थ्रेट परिकल्पनाओं का परीक्षण करने के लिए एनालिटिक्स और वैलिडेशन क्वेरीज़ को जोड़ती है। इसमें MITRE ATT&CK सुरक्षा फ्रेमवर्क के आधार पर इन पैटर्न को व्यवस्थित करने के लिए एक मैपिंग टूल शामिल है।

फ्रेमवर्क पूर्ण थ्रेट हंट लाइफसाइकिल को कवर करता है, जिसमें औपचारिक योजना और रिपोर्टिंग चक्र शामिल हैं। यह सुरक्षा परिकल्पनाओं को मान्य करने के लिए अपेक्षित सिस्टम लॉग और इवेंट डेटा को वास्तविक एनवायरनमेंट टेलीमेट्री के साथ मिलान करके डिटेक्शन इंजीनियरिंग विकास को सक्षम बनाता है।

Features

  • Threat Hunting Workflows - Provides a formalized framework for planning, executing, and reporting threat hunts to optimize security monitoring.
  • Notebook Analytics - Implements an interactive notebook environment for executing analytics queries to test security hypotheses.
  • Security Hunt Lifecycle Planning - Formalizes security operations through a repetitive sequence of planning, executing, and reporting phases.
  • Security Analysis Notebooks - Ships a research environment that combines analytics and validation queries to test threat hypotheses.
  • Detection Logic Development - Enables the creation and testing of behavioral signatures and detection logic using interactive notebooks.
  • Security Framework Mappings - Groups detection patterns and adversary tradecraft using standardized tactical security frameworks for consistent indexing.
  • Automated Hunting - Provides systematic workflows for guiding operators and AI through the research and assembly of threat hunting blueprints.
  • Interactive Threat Hunt Notebooks - Provides an environment for running interactive notebooks to test hypotheses against security telemetry datasets.
  • Threat Hunting Logic Libraries - Provides a structured collection of detection logic and adversary tradecraft to develop monitoring hypotheses.
  • MITRE ATT&CK Analysis - Uses the MITRE ATT&CK framework to organize behavioral patterns and detection rules into tactical groups.
  • Tradecraft Behavioral Modeling - Organizes detection logic and behavioral patterns into tactical groups based on standard security frameworks.
  • Hypothesis Validation Telemetry - Matches expected system logs and event data against actual environment telemetry to confirm threat presence.
  • Penetration Testing Toolkits - A playbook for developing threat hunting techniques.

स्टार हिस्ट्री

cyb3rward0g/threathunter-playbook के लिए स्टार हिस्ट्री चार्टcyb3rward0g/threathunter-playbook के लिए स्टार हिस्ट्री चार्ट

AI सर्च

और अधिक बेहतरीन रिपॉजिटरी खोजें

अपनी ज़रूरत को सरल भाषा में बताएं — AI हजारों क्यूरेटेड ओपन-सोर्स प्रोजेक्ट्स को प्रासंगिकता के आधार पर रैंक करता है।

Start searching with AI

ThreatHunter Playbook के ओपन-सोर्स विकल्प

समान ओपन-सोर्स प्रोजेक्ट्स, जो ThreatHunter Playbook के साथ साझा की गई सुविधाओं के आधार पर रैंक किए गए हैं।
  • vvard0g/threathunter-playbookVVard0g का अवतार

    VVard0g/ThreatHunter-Playbook

    4,594GitHub पर देखें↗

    ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed to inform threat hunt planning. It provides a security detection repository of validated queries and hypotheses, alongside an adversary tradecraft guide that details system behaviors and data sources associated with attacker techniques. The project focuses on the development of hunt blueprints and the standardization of detection logic. It integrates the MITRE ATT&CK framework to map detections and hypotheses to adversary tactics and techniques, ensuring coverage analysis is st

    Python
    GitHub पर देखें↗4,594
  • otrf/threathunter-playbookOTRF का अवतार

    OTRF/ThreatHunter-Playbook

    4,591GitHub पर देखें↗

    ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to standardize the security detection lifecycle. It functions as a community-driven repository for adversary tradecraft and detection logic, using interactive notebooks to combine technical documentation with executable analytics. The project provides a validation suite for testing security hypotheses against pre-recorded telemetry datasets. This ensures that detection logic is verified in local or cloud environments before being deployed to production. The framework covers security detec

    Pythondfirhunterhunting
    GitHub पर देखें↗4,591
  • withsecurelabs/chainsawWithSecureLabs का अवतार

    WithSecureLabs/chainsaw

    3,446GitHub पर देखें↗

    Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa

    Rustattackblueteamchainsaw
    GitHub पर देखें↗3,446
  • smicallef/spiderfootsmicallef का अवतार

    smicallef/spiderfoot

    18,189GitHub पर देखें↗

    SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati

    Pythonattacksurfacecticybersecurity
    GitHub पर देखें↗18,189
ThreatHunter Playbook के सभी 30 विकल्प देखें→

अक्सर पूछे जाने वाले प्रश्न

cyb3rward0g/threathunter-playbook क्या करता है?

ThreatHunter-Playbook थ्रेट हंटिंग प्लेबुक्स, डिटेक्शन इंजीनियरिंग वर्कफ़्लो और एडवर्सरी ट्रेडक्राफ्ट मॉडलिंग को मैनेज करने के लिए एक संरचित फ्रेमवर्क है। यह सुरक्षा निगरानी परिकल्पनाओं को विकसित करने के लिए व्यवहार संबंधी पैटर्न और डिटेक्शन नियमों को टैक्टिकल समूहों में व्यवस्थित करने के लिए एक सिस्टम प्रदान करता है।

cyb3rward0g/threathunter-playbook की मुख्य विशेषताएं क्या हैं?

cyb3rward0g/threathunter-playbook की मुख्य विशेषताएं हैं: Threat Hunting Workflows, Notebook Analytics, Security Hunt Lifecycle Planning, Security Analysis Notebooks, Detection Logic Development, Security Framework Mappings, Automated Hunting, Interactive Threat Hunt Notebooks।

cyb3rward0g/threathunter-playbook के कुछ ओपन-सोर्स विकल्प क्या हैं?

cyb3rward0g/threathunter-playbook के ओपन-सोर्स विकल्पों में शामिल हैं: vvard0g/threathunter-playbook — ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed… otrf/threathunter-playbook — ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to… withsecurelabs/chainsaw — Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It… smicallef/spiderfoot — SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the… neo23x0/loki — Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a… security-onion-solutions/securityonion — Security Onion is a security information and event management platform and network security monitoring suite. It…