A collection of tools and resources for threat hunters. Sections: - Hunting Tools: Open source tools for hunting like Velociraptor, osquery, GRR, ELK, Sysmon, and more. - Resources: Useful resources to get started in Threat Hunting. - Hunting with AI: Leveraging ChatGPT prompts for Threat Hunting. - Must Read: Articles and blog posts covering different aspects of Threat Hunting. - Custom Scripts: Tools and scripts to support different types of hunts.
FEATURES
ALTERNATIVES
A repository to aid Windows threat hunters in looking for common artifacts.
Repository for detection content with various types of rules and payloads.
Malware Patrol offers a range of threat intelligence solutions, including enterprise data feeds, DNS firewall, phishing threat intelligence, and small business protection.
RedEye is a visual analytic tool for enhancing Red and Blue Team operations.
TIH is an intelligence tool that helps you search for IOCs across multiple security feeds and APIs.
A threat hunting capability that leverages Sysmon and MITRE ATT&CK on Azure Sentinel
A database of Tor exit nodes with their corresponding IP addresses and timestamps.
OpenIOC editor for building and manipulating threat intelligence data with support for various systems.
PINNED

InfoSecHired
An AI-powered career platform that automates the creation of cybersecurity job application materials and provides company-specific insights for job seekers.

Mandos Brief Newsletter
A weekly newsletter providing cybersecurity leadership insights, industry updates, and strategic guidance for security professionals advancing to management positions.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Check Point CloudGuard WAF
A cloud-native web application and API security solution that uses contextual AI to protect against known and zero-day threats without signature-based detection.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.

Wiz
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.