A collection of companies that disclose adversary TTPs (Tactics, Techniques, and Procedures) after they have been breached, useful for analysis of intrusions launched by adversaries with measurable effects and impact. The collection includes a list of companies that have been breached, along with the breach date, adversary, and source of the information. The list includes well-known companies such as Microsoft, Cloudflare, Boeing, and many others, and provides valuable insights into the tactics and techniques used by adversaries.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Home for rules used by Elastic Security with code for unit testing, Kibana integration, and Red Team Automation.
A curated list of resources for learning about deploying, managing, and hunting with Microsoft Sysmon.
The Trystero Project is a threat intelligence platform that measures email security efficacy and provides various tools and resources, while VMware Carbon Black offers endpoint protection and workload security solutions.
A community-driven project sharing detection logic, adversary tradecraft, and resources to make detection development more efficient, following MITRE ATT&CK structure.
A mapping tool that correlates MITRE ATT&CK techniques with atomic tests and detection rules to analyze security detection coverage.
API for querying domain security information, categorization, and related data.
NECOMA focuses on data collection, threat analysis, and developing new cyberdefense mechanisms to protect infrastructure and endpoints.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.