A collection of tools and resources for threat hunters. Sections: - Hunting Tools: Open source tools for hunting like Velociraptor, osquery, GRR, ELK, Sysmon, and more. - Resources: Useful resources to get started in Threat Hunting. - Hunting with AI: Leveraging ChatGPT prompts for Threat Hunting. - Must Read: Articles and blog posts covering different aspects of Threat Hunting. - Custom Scripts: Tools and scripts to support different types of hunts.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
VirusTotal API v3 is a threat intelligence platform for scanning files, URLs, and IP addresses, and retrieving reports on threat reputation and context.
A collection of companies that disclose adversary TTPs after being breached, useful for analysis of intrusions.
CRITs is an open source malware and threat repository for collaborative threat defense and analysis.
A comprehensive Threat Intelligence Program Management Solution for managing the entire CTI lifecycle.
A free software that calculates the security ranking of Internet Service Providers to detect malicious activities.
FraudGuard is a service that provides real-time internet traffic analysis and IP tracking to help validate usage and prevent fraud.
VX-Underground is a vast online repository of malware samples, featuring various collections for cybersecurity professionals and researchers to analyze and combat cyber threats.
Malware Patrol offers a range of threat intelligence solutions, including enterprise data feeds, DNS firewall, phishing threat intelligence, and small business protection.
Packet Storm is a global security resource providing around-the-clock information and tools to mitigate personal data and fiscal loss on a global scale.
PINNED

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.