GCTI's open source detection signatures repository contains a collection of open-source detection signatures for various malware and threats. These signatures are designed to be used with various security tools and systems to detect and prevent malicious activities. The repository is maintained by GCTI and is updated regularly to include new signatures and improve detection capabilities.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Tool for visualizing correspondences between YARA ruleset and samples
Powershell Threat Hunting Module for scanning remote endpoints and collecting comprehensive information.
Repository for detection content with various types of rules and payloads.
A curated collection of Sigma & Yara rules and Indicators of Compromise (IOCs) for threat detection and malware identification.
HYAS Insight is a threat intelligence platform that provides infrastructure intelligence and cyber threat hunting capabilities for security operations, fraud investigations, and adversary profiling.
SecurityTrails API provides access to a vast repository of historical DNS lookups, WHOIS records, hostnames, and domains for cyber forensics and investigations.
Search engine for Windows executable files and hashes, providing insights into file prevalence, behavior, and security information.
Sigma is a generic and open signature format for SIEM systems and other security tools to detect and respond to threats.
A tool for identifying potential security threats by fetching known URLs and filtering out URLs with open redirection or SSRF parameters.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.