33 个仓库
General-purpose frameworks and utilities for threat hunting and security analysis.
Explore 33 awesome GitHub repositories matching part of an awesome list · Detection and Hunting Tools. Refine with filters or upvote what's useful.
YARA is a pattern matching engine and binary analysis tool used to identify and classify malware samples. It functions as a malware research framework that allows for the definition of file descriptions and detection rules to find indicators of compromise within binaries. The system enables the creation of custom detection rules using strings, wildcards, and regular expressions. These rules use boolean logic to match textual or binary patterns, allowing for the classification of files into specific malware families and the automation of threat intelligence. The engine utilizes Aho-Corasick s
Pattern matching tool for identifying malicious files.
Dispatch is an incident response orchestration platform that automates the coordination of detection, participant assembly, and task tracking across existing communication and project management tools. It provides a web-configurable state machine to manage incident lifecycle transitions, with template-driven incident models that define types, priorities, and severity levels. The platform enforces role-based access control to map user roles to specific actions and data access, while maintaining a database-backed audit trail of all incident events and system changes for compliance and post-incid
Orchestration framework for crisis management.
capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities such as API calls, byte sequences, and structural patterns without executing the code. It supports multiple file formats including PE, ELF, .NET, and shellcode, and can also process runtime behavior traces from sandbox reports generated by CAPE, DRAKVUF, or VMRay. The tool integrates directly with reverse engineering environments through plugins for IDA Pro and Ghidra, allowing analysts to view capability matches and author detection rules within their disassembler of choice. C
Identifies capabilities within executable files.
DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms. The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients. The environment includes a telemetry pipeline that aggre
Automated lab environment setup for security tooling and logging.
IntelOwl 是一个威胁情报平台和安全编排引擎,旨在聚合、分析和丰富安全可观测数据。它作为一个安全事件调查工具和威胁情报聚合器,从各种内部和外部来源收集有关文件、域名和 IP 地址的数据。 该系统通过基于行动手册(Playbook)的工作流自动化脱颖而出,允许用户定义可重用的分析任务序列,根据先前的输出触发后续作业。它将分散的安全数据统一为通用模式,并利用协议级访问控制来根据数据敏感性限制分析器的执行。 该平台涵盖了广泛的功能,包括事件驱动的指标摄入、自动化安全运营中心(SOC)工作流和情报丰富。它提供了用于组织调查的工具,并通过仪表板可视化分析结果以关联发现。
OSINT solution for gathering threat intelligence at scale.
HELK 是一个容器化的安全信息和事件管理(SIEM)环境及威胁狩猎平台。它提供了一个以安全为中心的 ELK 堆栈部署,将 Elasticsearch、Logstash 和 Kibana 结合在一起,成为一个用于调查日志和发现网络及系统安全数据中隐藏模式的专业平台。 该项目作为安全数据科学套件,集成了交互式计算笔记本和分布式处理工具,以对安全日志运行机器学习和图分析。这允许通过基于图的关系映射来识别隐藏的攻击模式和异常。 该平台涵盖了广泛的安全运营领域,包括 SIEM 部署、日志聚合和基于索引的日志搜索。它利用基于容器的基础设施来部署用于安全日志分析和威胁狩猎的全套工具。
An advanced hunting platform based on the Elastic stack.
Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
Linux distribution for security monitoring and log management.
Web app that provides basic navigation and annotation of ATT&CK matrices
Provides navigation and annotation for MITRE ATT&CK matrices.
DeepBlueCLI - a PowerShell Module for Threat Hunting via Windows Event Logs
PowerShell module for hunting via Windows event logs.
BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.
Serverless framework for real-time malware detection.
Virtual Machine for Adversary Emulation and Threat Hunting
Virtual machine environment for adversary emulation and hunting.
A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
Splunk application mapped to MITRE ATT&CK techniques.
Tenzir is the data pipeline engine for security teams.
Telemetry engine for data-driven security investigations.
CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.
Performs remote incident response and hunting on Windows.
A powerful and user-friendly browser extension that streamlines investigations for security professionals.
Browser extension for streamlining security investigations.
🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.
Message broker for connecting disparate security tools.
Synthetic Adversarial Log Objects (SALO) is a framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event. The purpose of this framework is to allow security practitioners, data scientists, and researchers the ability to…
Generates log events for testing without infrastructure.
Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)
CloudTrail monitoring using event query language.
A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!
Converts network logs to Elastic/OpenSearch formats.
Collection of alerts and queries for Azure Sentinel.