awesome-repositories.com
ब्लॉग
MCP
awesome-repositories.com

AI-संचालित खोज के साथ बेहतरीन ओपन-सोर्स रिपॉजिटरी खोजें।

एक्सप्लोर करेंक्यूरेटेड खोजेंओपन-सोर्स विकल्पसेल्फ-होस्टेड सॉफ्टवेयरब्लॉगसाइटमैप
प्रोजेक्टMCP सर्वरहमारे बारे मेंहम रैंकिंग कैसे करते हैंप्रेस
कानूनीगोपनीयताशर्तें
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to cyb3rward0g/threathunter-playbook

Open-source alternatives to ThreatHunter Playbook

30 open-source projects similar to cyb3rward0g/threathunter-playbook, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best ThreatHunter Playbook alternative.

  • vvard0g/threathunter-playbookVVard0g का अवतार

    VVard0g/ThreatHunter-Playbook

    4,594GitHub पर देखें↗

    ThreatHunter-Playbook is a collection of standardized playbooks, detection libraries, and tradecraft guides designed to inform threat hunt planning. It provides a security detection repository of validated queries and hypotheses, alongside an adversary tradecraft guide that details system behaviors and data sources associated with attacker techniques. The project focuses on the development of hunt blueprints and the standardization of detection logic. It integrates the MITRE ATT&CK framework to map detections and hypotheses to adversary tactics and techniques, ensuring coverage analysis is st

    Python
    GitHub पर देखें↗4,594
  • otrf/threathunter-playbookOTRF का अवतार

    OTRF/ThreatHunter-Playbook

    4,591GitHub पर देखें↗

    ThreatHunter-Playbook is a threat hunting playbook framework and detection engineering workflow designed to standardize the security detection lifecycle. It functions as a community-driven repository for adversary tradecraft and detection logic, using interactive notebooks to combine technical documentation with executable analytics. The project provides a validation suite for testing security hypotheses against pre-recorded telemetry datasets. This ensures that detection logic is verified in local or cloud environments before being deployed to production. The framework covers security detec

    Pythondfirhunterhunting
    GitHub पर देखें↗4,591
  • withsecurelabs/chainsawWithSecureLabs का अवतार

    WithSecureLabs/chainsaw

    3,446GitHub पर देखें↗

    Chainsaw is a Windows forensic analysis tool used for parsing system databases and extracting security artefacts. It functions as a forensic artefact extractor and a scanner for identifying security threats and log tampering within Windows event logs. The project distinguishes itself by implementing a Sigma rule forensic scanner that applies standardized detection logic and custom rule sets to event logs and forensic artefacts. It enables threat hunting workflows by matching event data against patterns to identify malicious activity, lateral movement, and brute force attacks. The tool's capa

    Rustattackblueteamchainsaw
    GitHub पर देखें↗3,446

AI सर्च

और अधिक बेहतरीन रिपॉजिटरी खोजें

अपनी ज़रूरत को सरल भाषा में बताएं — AI हजारों क्यूरेटेड ओपन-सोर्स प्रोजेक्ट्स को प्रासंगिकता के आधार पर रैंक करता है।

Find more with AI search
  • smicallef/spiderfootsmicallef का अवतार

    smicallef/spiderfoot

    18,189GitHub पर देखें↗

    SpiderFoot is an open-source reconnaissance and intelligence automation framework designed to streamline the collection and correlation of data for security investigations. It functions as a comprehensive platform that automates the querying of hundreds of public data sources to map digital footprints, identify exposed assets, and uncover potential security threats across an organization's external perimeter. The platform distinguishes itself through a modular, plugin-based architecture that executes data gathering tasks in parallel, supported by a directed graph data model that tracks relati

    Pythonattacksurfacecticybersecurity
    GitHub पर देखें↗18,189
  • security-onion-solutions/securityonionSecurity-Onion-Solutions का अवतार

    Security-Onion-Solutions/securityonion

    4,661GitHub पर देखें↗

    Security Onion is a security information and event management platform and network security monitoring suite. It functions as an intrusion detection system and a network traffic analysis tool designed to identify malicious activity and network intrusions through signature-based detection and host-based monitoring. The platform integrates a security case management system to organize investigations by tracking detections and grouping related security events. It provides capabilities for full packet capture, network metadata extraction, and the collection and indexing of security logs from dive

    Shell
    GitHub पर देखें↗4,661
  • neo23x0/lokiNeo23x0 का अवतार

    Neo23x0/Loki

    3,763GitHub पर देखें↗

    Loki is an endpoint detection tool, forensic artifact analyzer, and threat intelligence scanner. It functions as a YARA-based indicator of compromise scanner designed to identify malicious persistence mechanisms, web shells, and unauthorized administration tools across local and remote systems. The project distinguishes itself by integrating multi-source threat intelligence, allowing for the loading of custom signature sets and encrypted indicators. It combines hash-based artifact detection with YARA rule execution to scan files, process memory, and registry hives for known malicious byte seq

    Python
    GitHub पर देखें↗3,763
  • yamato-security/hayabusaYamato-Security का अवतार

    Yamato-Security/hayabusa

    3,027GitHub पर देखें↗

    Hayabusa is a Windows event log analyzer, threat hunting tool, and forensic timeline generator. It functions as a detection engine that applies threat patterns to logs to identify suspicious behavior and security threats. The project distinguishes itself through the ability to synchronize detection rules from remote repositories and tune risk levels to prioritize critical alerts. It also provides specialized forensic capabilities, such as extracting event log data into chronological records for incident response investigations. The tool's broader capabilities include security log enrichment

    Rustattackcybersecuritydetection
    GitHub पर देखें↗3,027
  • cyb3rward0g/helkCyb3rWard0g का अवतार

    Cyb3rWard0g/HELK

    3,926GitHub पर देखें↗

    HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data. The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and an

    Jupyter Notebook
    GitHub पर देखें↗3,926
  • neo23x0/sigmaNeo23x0 का अवतार

    Neo23x0/sigma

    10,591GitHub पर देखें↗

    Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It provides a vendor-neutral system for defining security event patterns in YAML, ensuring that detection logic remains portable across different monitoring platforms. The project maintains a curated library of peer-reviewed detection rules that identify threats and compliance violations. This standardized approach allows for the exchange of threat hunting logic and the translation of generic signatures into specific queries for various security information and event management systems

    Python
    GitHub पर देखें↗10,591
  • comodosecurity/openedrComodoSecurity का अवतार

    ComodoSecurity/openedr

    2,603GitHub पर देखें↗

    OpenEDR is an endpoint detection and response platform designed to collect telemetry and monitor system activity to identify security breaches. It functions as a host-based intrusion detection system and telemetry collector, gathering detailed data on process, network, and file activity. The system includes a dockerized security stack that bundles search, logging, and visualization tools into containers for analyzing endpoint telemetry. It features a security event visualizer that maps process lineage and indexes logs to facilitate root-cause analysis of attacks. The platform provides capabi

    C++
    GitHub पर देखें↗2,603
  • bypass007/emergency-response-notesBypass007 का अवतार

    Bypass007/Emergency-Response-Notes

    5,551GitHub पर देखें↗

    Emergency-Response-Notes is a collection of technical reference documentation and playbooks used for performing forensic analysis, incident response, intrusion identification, and malware remediation. It serves as an incident response knowledge base and an intrusion analysis framework to help identify web shells, hidden backdoors, and persistence mechanisms used during security attacks. The project utilizes a case-study-based knowledge base to map real-world attack scenarios to specific mitigation and recovery steps. It provides a digital forensics playbook and a malware remediation guide for

    GitHub पर देखें↗5,551
  • k8gege/k8toolsk8gege का अवतार

    k8gege/K8tools

    6,167GitHub पर देखें↗

    K8tools is a multi-stage attack framework that combines memory-only payload execution, credential testing, port forwarding, privilege escalation, and physical USB-based keystroke injection for comprehensive system compromise. At its core, the Ladon PowerShell module loads a multi-function scanner directly into memory, enabling command execution without writing files to disk, while supporting memory-only payload delivery that downloads and runs obfuscated shellcode or PowerShell commands to evade antivirus detection. The framework distinguishes itself through its breadth of integrated capabili

    PowerShell0daybrute-forcebypass
    GitHub पर देखें↗6,167
  • mukul975/anthropic-cybersecurity-skillsmukul975 का अवतार

    mukul975/Anthropic-Cybersecurity-Skills

    19,327GitHub पर देखें↗

    817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 29 security domains · Apache 2.0

    Pythonai-agentsclaude-codecloud-security
    GitHub पर देखें↗19,327
  • perspective-dev/perspectiveperspective-dev का अवतार

    perspective-dev/perspective

    10,981GitHub पर देखें↗

    Perspective is a columnar data analytics engine and high-performance visualization component powered by WebAssembly. It provides a system for analyzing and visualizing large or streaming datasets through interactive data grids and charts, utilizing a compiled binary to achieve near-native performance within the browser. The project distinguishes itself through a WebSocket-based data streaming interface and deep Apache Arrow integration, which minimize memory overhead when synchronizing tables between servers and clients. It acts as a remote query proxy capable of translating visualization con

    C++analyticsbidata-visualization
    GitHub पर देखें↗10,981
  • microsoft/security-101microsoft का अवतार

    microsoft/Security-101

    6,203GitHub पर देखें↗

    Security-101 is a vendor-agnostic, foundational cybersecurity learning curriculum organized into modular, framework-aligned modules. It is designed to build core knowledge across multiple security domains without tying content to specific products or platforms, making it suitable for both beginners and professionals seeking a structured introduction to the field. The curriculum is built around established security frameworks, including the MITRE ATT&CK framework for standardized threat analysis and the NIST Cybersecurity Framework for incident response workflows. It covers a broad range of do

    HTMLappseccia-triaddata-protection
    GitHub पर देखें↗6,203
  • finos/perspectivefinos का अवतार

    finos/perspective

    10,967GitHub पर देखें↗

    Perspective is a columnar data analytics library and streaming data visualization engine. It provides an interactive data grid component and notebook analytics widgets designed for processing high-volume data and rendering interactive charts and grids. The system utilizes a high-performance query engine to enable real-time data analysis and streaming dataset visualization. It supports the creation of customizable dashboards and reports that update automatically as new data arrives without requiring full dataset reloads. The project covers large-scale dataset analytics through a schema-driven

    C++
    GitHub पर देखें↗10,967
  • fireeye/capafireeye का अवतार

    fireeye/capa

    6,062GitHub पर देखें↗

    capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities such as API calls, byte sequences, and structural patterns without executing the code. It supports multiple file formats including PE, ELF, .NET, and shellcode, and can also process runtime behavior traces from sandbox reports generated by CAPE, DRAKVUF, or VMRay. The tool integrates directly with reverse engineering environments through plugins for IDA Pro and Ghidra, allowing analysts to view capability matches and author detection rules within their disassembler of choice. C

    Python
    GitHub पर देखें↗6,062
  • mandiant/capamandiant का अवतार

    mandiant/capa

    6,062GitHub पर देखें↗

    capa is a binary capability scanner that identifies high-level behaviors and actions an executable can perform, such as network communication or file manipulation. It functions as a malware behavior analysis tool and a MITRE ATT&CK mapping framework, scanning PE, ELF, .NET, and shellcode files through both static analysis and dynamic sandbox report processing. The tool distinguishes itself through a YAML-based detection rule engine that defines detection logic in human-readable files, with conditions expressed as feature combinations and logical operators. It integrates with IDA Pro, Ghidra,

    Python
    GitHub पर देखें↗6,062
  • cloud-architekt/azuread-attack-defenseCloud-Architekt का अवतार

    Cloud-Architekt/AzureAD-Attack-Defense

    2,471GitHub पर देखें↗
    PowerShellazureactivedirectoryitdrmicrosoftentraid
    GitHub पर देखें↗2,471
  • thehive-project/thehiveTheHive-Project का अवतार

    TheHive-Project/TheHive

    3,891GitHub पर देखें↗

    TheHive is a security incident response platform and multi-tenant case management system. It functions as a Security Orchestration, Automation, and Response (SOAR) tool and a threat intelligence platform designed to coordinate security investigations by managing alerts, cases, and observables. The platform is distinguished by its multi-tenant architecture, which isolates data across different organizations while supporting selective cross-tenant sharing. It features a SOAR automation engine capable of executing sandboxed JavaScript logic to automate workflows and trigger response actions thro

    Scalaanalyzerapicortex
    GitHub पर देखें↗3,891
  • knownsec/pocsuite3knownsec का अवतार

    knownsec/pocsuite3

    3,853GitHub पर देखें↗

    Pocsuite3 is a modular vulnerability testing framework designed for the development and execution of security assessment scripts. It provides a comprehensive toolkit for remote vulnerability verification and exploitation, enabling users to automate the identification of security flaws across network targets. The framework is built on an object-oriented scripting architecture that allows for the creation of custom security modules and plugins. It distinguishes itself through a highly extensible design that supports asynchronous task execution for large-scale infrastructure assessments, alongsi

    Pythonpentestingpythonsecurity
    GitHub पर देखें↗3,853
  • brannondorsey/wifi-crackingbrannondorsey का अवतार

    brannondorsey/wifi-cracking

    12,399GitHub पर देखें↗

    This project is a WPA Wi-Fi cracking toolkit designed for capturing authentication handshakes and recovering WPA/WPA2 passwords. It provides specialized utilities for scanning wireless networks, obfuscating hardware addresses, and generating password lists to facilitate security audits. The toolkit differentiates itself through a focused workflow that combines handshake capture tools with a password wordlist generator. It enables the interception of the four-way authentication process between wireless clients and access points and utilizes these captured credentials for recovery via dictionar

    aircrack-ngcrackinghacking
    GitHub पर देखें↗12,399
  • bluscreenofjeff/red-team-infrastructure-wikibluscreenofjeff का अवतार

    bluscreenofjeff/Red-Team-Infrastructure-Wiki

    4,498GitHub पर देखें↗

    This project is a collection of technical resources, blueprints, and guides for building resilient and stealthy red team infrastructure. It provides a comprehensive framework for designing offensive security environments that resist detection and remain operational throughout security engagements. The repository distinguishes itself through detailed playbooks for adversary simulation and hardening manuals. It covers advanced obfuscation techniques such as domain fronting, the use of platform-as-a-service redirectors, and the leveraging of third-party content sites to inherit domain reputation

    GitHub पर देखें↗4,498
  • apsdehal/awesome-ctfapsdehal का अवतार

    apsdehal/awesome-ctf

    11,614GitHub पर देखें↗

    This project is a comprehensive directory of software utilities, frameworks, and educational resources designed for cybersecurity competitions and offensive security research. It serves as a centralized index for tools used in cryptography, forensics, reverse engineering, and web exploitation, while providing structured materials for training and skill development. The repository distinguishes itself through a community-driven maintenance model that aggregates and organizes technical resources into a searchable, hierarchical structure. It facilitates knowledge transfer by cataloging expert pr

    JavaScriptawesomectfpenetration
    GitHub पर देखें↗11,614
  • deralexxx/security-apisderalexxx का अवतार

    deralexxx/security-apis

    983GitHub पर देखें↗

    A collective list of public APIs for use in security. Contributions welcome

    GitHub पर देखें↗983
  • darthton/blackboneDarthTon का अवतार

    DarthTon/Blackbone

    5,431GitHub पर देखें↗

    Blackbone is a collection of specialized tools for memory scanning, process injection, and kernel-driver interfaces used to manipulate the Windows execution environment. It provides a framework for executing remote code, mapping portable executable images, and managing threads across different process boundaries. The project includes a kernel memory driver to access kernel memory and modify handle rights to hide allocations from user-mode detection. It also features a library for intercepting function calls in remote processes using software interrupts and hardware breakpoints. The toolkit c

    C++
    GitHub पर देखें↗5,431
  • devsecops/awesome-devsecopsdevsecops का अवतार

    devsecops/awesome-devsecops

    5,306GitHub पर देखें↗
    devopsdevsecopspodcast
    GitHub पर देखें↗5,306
  • diasdavid/awesome-hacking-spotsdiasdavid का अवतार

    diasdavid/awesome-hacking-spots

    1,122GitHub पर देखें↗

    :computer: :coffee: List of Awesome Hacking Locations, organised by Country and City, listing if it features power and wifi

    GitHub पर देखें↗1,122
  • djadmin/awesome-bug-bountydjadmin का अवतार

    djadmin/awesome-bug-bounty

    5,708GitHub पर देखें↗

    A comprehensive curated list of available Bug Bounty & Disclosure Programs and Write-ups.

    GitHub पर देखें↗5,708
  • bluscreenofjeff/aggressorscriptsbluscreenofjeff का अवतार

    bluscreenofjeff/AggressorScripts

    896GitHub पर देखें↗

    Aggressor scripts for use with Cobalt Strike 3.0+

    GitHub पर देखें↗896