EchoTrail is a search engine for Windows executable files and hashes, providing insights into file prevalence, behavior, and security information to help identify suspicious files. With EchoTrail, you can search for an executable file or hash and get information on its prevalence in Windows environments, including its rank, most common filepath, and security information. The platform also provides an advanced search feature, allowing users to refine their searches and get more detailed results.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Cortex is a tool for analyzing observables at scale and automating threat intelligence, digital forensics, and incident response.
NECOMA focuses on data collection, threat analysis, and developing new cyberdefense mechanisms to protect infrastructure and endpoints.
C# wrapper around Yara pattern matching library with Loki and Yara signature support.
Unified repository for Microsoft Sentinel and Microsoft 365 Defender containing security content, detections, queries, playbooks, and resources to secure environments and hunt for threats.
Repository containing MITRE ATT&CK and CAPEC datasets in STIX 2.0 for cybersecurity threat modeling.
An informational repo about hunting for adversaries in your IT environment.
Forager is a threat intelligence tool that simplifies the retrieval, storage, and maintenance of threat data with a user-friendly interface and support for various data sources.
A collection of public YARA signatures for various malware families.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.