Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
awesome-lists — Kuratierte Sammlung von Threat-Intelligence-Feeds, IoC-Listen, YARA-Regeln und DFIR-Tool-Referenzen für SOC/CERT/CTI-Erkennung und Incident Response. | Kitploit
Tools/GitHubGitHub/mthcht/awesome-lists
Management von Indicators of Compromise (IOC)Bedrohungsfeeds & AggregatorenDigitale ForensikBedrohungsanalyseLernen & BildungIncident ResponseKuratierte Ressourcen
GitHubmthcht/awesome-lists

awesome-lists

Kuratierte Sammlung von Threat-Intelligence-Feeds, IoC-Listen, YARA-Regeln und DFIR-Tool-Referenzen für SOC/CERT/CTI-Erkennung und Incident Response.

Repository anzeigen
1.9k2258vor 2h 6mVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

Sicherheitslisten für SOC/DFIR-Erkennungen Awesome

dt

🐾 Threat Hunting:

  • ThreatHunting keywords Site
  • ThreatHunting keywords Lists
  • ThreatHunting Yara rules

ThreatHunting-Suchen

  • Windows-Dienste-Suchen
  • User-Agents-Suchen
  • DNS-over-HTTPS-Suchen
  • Suchen nach verdächtigen TLDs
  • HijackLibs-Suchen
  • Phishing- & DNSTWIST-Suchen
  • Suchen zu Browser-Erweiterungen
  • C2, das sich in aller Offenheit versteckt
  • HTML-Smuggling-Artefakte
  • Suchen zu PSEXEC und ähnlichen Tools
  • Erkennung von Time Slipping
  • Verdächtige Named Pipes

📂 Meine Erkennungslisten

  • 📋 Listen: https://github.com/mthcht/awesome-lists/tree/main/Lists
  • 🕵️‍♂️ ThreatHunting-Leitfäden: https://mthcht.medium.com/list/threat-hunting-708624e9266f
  • 🚰 Verdächtige Named Pipes: suspicious_named_pipe_list.csv
  • 🌐 Verdächtige TLDs (automatisch aktualisiert): [suspicious_TLDs]
  • 🌐 Verdächtige ASNs (automatisch aktualisiert): [suspicious ASNs]
  • 🌐 FYI Maxmind GeoIP-Datenbank (automatisch aktualisiert): GeoIP DB
  • 🆔 Verdächtige OAuth-App-IDs: OauthSentry
  • 🔧 Verdächtige Windows-Dienste: suspicious_windows_services_names_list.csv
  • ⏲️ Verdächtige Windows-Aufgaben: suspicious_windows_tasks_list.csv
  • 🚪 Verdächtige Zielports: suspicious_ports_list.csv
  • 🛡️ Verdächtige Firewall-Regeln: suspicious_windows_firewall_rules_list.csv
  • 🆔 Verdächtige User-Agents: suspicious_http_user_agents_list.csv
  • 🔏 Verdächtige CERT-Signer: [suspicious CERTS]
  • 📇 Verdächtige USB-IDs: suspicious_usb_ids_list.csv
  • 🏷️ Verdächtige Mutex-Namen: suspicious_mutex_names_list.csv

Ich aktualisiere die meisten dieser Listen regelmäßig nach jedem Tool, das ich in meinem Projekt Erkennungs-Keywords analysiere.

Weitere Listen

🛡️ DFIR:

  • 🔥 EricZimmerman Tools 🔥
  • usnjrnl_rewind
  • dfir-orc
  • dfir-orc-config
  • Arsenal Recon Forensik-Tools
  • Splunk4DFIR
  • dfiq
  • Mindmaps
  • arfifacts-Liste - DFIRArtifactMuseum
  • arfifacts-Liste - ForensicArtifacts
  • Autopsy
  • SleuthKit
  • [OS] SIFT Workstation
  • [OS] Remnux
  • [OS] sof-elk
  • [OS] tsurugi
  • [OS] DEFT
  • [OS] Flare VM
  • PSBits
  • Yara - Threat Hunting + TH
  • Yara - Forge
  • capa
  • Malcontent
  • [Event-Parser] evtx

🚫 IOC-Feeds/Blacklists:

  • ABUSE.CH BLACKLISTS
  • Blocklisten
  • DNS-Blockliste
  • Phishing-Blockliste
  • Binary Defense IP-Blockliste
  • C2IntelFeeds
  • Volexity TI
  • Open-Source-TI
  • C2 Tracker
  • Unit42 IOC
  • Sekoia IOC
  • Unit42 Zeitnahe IOCs
  • Unit42 Artikel-IOCs
  • ThreatFOX IOC
  • Zscaler ThreatLabz IOC
  • Zscaler ThreatLabz Ransomware-Lösegeldnotizen
  • experiant.ca
  • Sophos-Lab-IOCs
  • ESET-Research-IOCs
  • ExecuteMalware IOC
  • Cisco Talos IOC
  • Elastic Lab IOC
  • Blackorbid APT-Bericht-IOCs

🐙 GitHub

  • Weitere GitHub-Listen

🖥️ SIEM/SOC/PurpleTeam-bezogen:

- [EDR Telemetry](https://github.com/tsale/EDR-Telemetry) - [PurpleTeam Scripts](https://github.com/mthcht/Purpleteam) - [Awesome-SOC](https://github.com/cyb3rxp/awesome-soc) - [Awesome SOC analyst](https://github.com/st0pp3r/awesome-soc-analyst) - [Threat-Hunting mit Splunk](https://github.com/mthcht/ThreatHunting-Keywords) - [Detection-Listen](https://github.com/mthcht/awesome-lists/Lists) - [PurpleTeam atomics](https://github.com/redcanaryco/atomic-red-team)

📊 TI TTP/Framework/Modell/Tracker

  • Von Ransomware-Gruppen verwendete Tools - @BushidoToken
  • Von russischen APT-Gruppen verwendete Tools
  • Gruppen zugeordnete Tools (teilweise)
  • Techniken - MITRE ATT&CK
  • Taktiken - MITRE ATT&CK
  • Matrix der Namenskonventionen für Gruppen & Operationen
  • Mitigationen - MITRE ATT&CK
  • ATT&CK-Matrix-Navigator
  • Alle MITRE-Daten im xlsx-Format
  • Von Threat-Actor-Gruppen verwendete Tools - MITRE ATT&CK
  • atomic-red-team
  • redcanary Threat-Detection-Bericht
  • The-Unified-Kill-Chain
  • TTP-Pyramide
  • Pyramide des Schmerzes
  • Cyber-Kill-Chain
  • MITRE D3FEND
  • MITRE CAPEC
  • MITRE CAR
  • MITRE DeTTECT
  • MITRE-PRE-ATT&CK-Techniken

🕵️‍♂️ Untersuchung

📊 TI-Checks

  • Virustotal
  • SpamHaus
  • app.spur.us
  • AbuseIPDB
  • Telegram-BOT-Hunting
  • Malwarebazaar
  • emailrep
  • dnsdumpster
  • nslookup.io
  • cloudfare URL-Scan
  • Proxy-IP-Check - proxycheck.io
  • IP-Reputations-Check criminalip
  • Proxy-IP-Check - iphub.info
  • shodan
  • Onyphe
  • haveibeenpwned
  • leakcheck.io
  • Censys
  • cybergordon (URL-Reputations-Check)
  • threatminer
  • urlscan
  • Apptotal (Analyse von Apps und Erweiterungen)
  • urlquery
  • cloudfare-Scanner
  • scamsearch.io
  • scamdb.net
  • urlvoid

🔬 Sandbox / Emulation

  • Sandbox Anyrun
  • triage
  • capesandbox
  • joesandbox
  • filescan.io
  • Hybrid Analysis
  • virustotal
  • threat zone
  • vmray
  • kaspersky opentip
  • speakeasy (Emulation im Kernel- und Benutzermodus)
  • DOGGuard
  • Kaspersky Threat Intelligence Portal

🧩 Datenmanipulation

  • CyberChef
  • jsoncrack
  • Grok-Debugger
  • JS-Deobfuscator
  • PCAP-Online-Analysator
  • Hash-Rechner
  • regex101
  • PCAP-Analysator online
  • Javascript-Deobfuscator - deobfuscate.relative.im
  • Javascript-Deobfuscator - de4js
  • JSONViewer
  • TextMechanic
  • UrlEncode.org
  • TextFixer
  • RegExr
  • TextUtils
  • TextCompactor
  • Pretty Diff
  • XML Tree
  • Online-XML-Formatierer und -Beautifier
  • XML-Escape-Tool
  • DiffChecker
  • CSVJSON
  • HTML-Formatierer
  • Text-Tool
  • String-Manipulations-Tool

📡 Detection-Ressourcen

  • Detection-Listen
  • MITRE-Techniken
  • MITRE-Updates
  • MITRE D3fend
  • MITRE Navigator
  • MITRE-Datenquellen
  • GTFOBIN
  • LOLBAS
  • LOTS
  • LOLRMM
  • loldrivers
  • LOLRMM
  • LOLC2
  • LOLESXI
  • WTFBIN
  • Sigma
  • Splunk-Regeln
  • Elastic-Regeln
  • DFIR-Report-Sigma-Regeln
  • JoeSecurity-Sigma-Regeln
  • mdecrevoisier-Sigma-Regeln
  • P4T12ICK-Sigma-Regeln
  • tsale-Sigma-Regeln
  • Liste der Detection-Ressourcen

🌐 Sicherheitsnachrichten

- [Adam Chester Blog-Feed](https://blog.xpnsec.com/rss.xml) - [ahnlab APT-Feed](https://asec.ahnlab.com/en/category/apt-en/feed/) - [ahnlab CERT-Feed](https://asec.ahnlab.com/en/category/cert-en/feed) - [ahnlab Phishing-Feed](https://asec.ahnlab.com/en/category/phishing-scam-en/feed) - [ahnlab Trend-Feed](https://asec.ahnlab.com/en/category/trend-en/feed) - [Akamai Blog-Feed](https://feeds.feedburner.com/akamai/blog) - [Any.run Malware-Analyse-Blog-Feed](https://any.run/cybersecurity-blog/category/malware-analysis/feed/) - [Avast Blog-Feed](https://blog.avast.com/rss.xml) - [badsectorlabs Last week in security - Redteam](https://blog.badsectorlabs.com/feeds/all.atom.xml) - [bi-zone Blog-Feed](https://medium.com/feed/@bi-zone) - [bitdefender Labs-Feed](https://www.bitdefender.com/nuxt/api/en-us/rss/labs/) - [binarydefense Blog-Feed](https://www.binarydefense.com/feed/) - [Blackberry-Blog](https://blogs.blackberry.com/en/home) - [Bleepingcomputer-Feed](https://www.bleepingcomputer.com/feed/) - [bleepingcomputer-Feed](https://www.bleepingcomputer.com/feed/) - [Broadcom Blog-Feed](https://sed-cms.broadcom.com/rss/v1/blogs/rss.xml) - [CERT FR Warnungen](https://www.cert.ssi.gouv.fr/alerte/) - [CERT FR Hinweise](https://www.cert.ssi.gouv.fr/avis/) - [CERT LV-Feed](https://cert.lv/en/feed/rss/all) - [CERT PL-Feed](https://cert.pl/en/rss.xml) - [CERT SE-Feed](https://www.cert.se/feed.rss) - [CERT SI-Feed](https://www.cert.si/en/category/news/feed/) - [CERT UA-Feed](https://cert.gov.ua/api/articles/rss) - [CERT-FR](https://www.cert.ssi.gouv.fr/) - [Checkpoint Research-Feed](https://research.checkpoint.com/feed) - [CIRT bd-Feed](https://www.cirt.gov.bd/feed/) - [CISA Nachrichten-Feed](https://www.cisa.gov/cybersecurity-advisories/all.xml) - [CISA Nachrichten](https://www.cisa.gov/news-events/news) - [Cisco Talos](https://www.talosintelligence.com/) - [Claroty Team82-Forschung](https://claroty.com/team82/research/) - [Cloudfare Sicherheits-Feed](https://blog.cloudflare.com/tag/security/rss) - [Clément Notin-Feed](https://clement.notin.org/feed.xml) - [CrowdStrike Counter Adversary Operations Blog](https://www.crowdstrike.com/en-us/blog/category.counter-adversary-operations/) - [deepinstinct Blog](https://www.deepinstinct.com/blog) - [detect.fyi](https://detect.fyi/) - [Detection Engineering Weekly](https://www.detectionengineering.net/) - [DFIR Wochennachrichten](https://thisweekin4n6.com/) - [DFIR Wochennachrichten-Feed](https://thisweekin4n6.wordpress.com/feed/) - [drweb Virus-Warn-Feed](https://news.drweb.com/rss/get/?c=9) - [EclecticIQ Threat Intel](https://www-eclecticiq-com.sandbox.hs-sites.com/blog?type=intelligence-research#overview) - [Elastic Security Labs Blog](https://www.elastic.co/security-labs) - [elastic Security-Labs-Blog-Feed](https://www.elastic.co/security-labs/rss/feed.xml) - [EricaZelic Blog](https://ericazelic.medium.com/) - [Forcepoint Lab-Blog](https://www.forcepoint.com/blog/x-labs) - [Genians Threat-Intel-Feed](https://www.genians.co.kr/blog/threat_intelligence/rss.xml) - [gi7w0rm Threat-Intel-Feed](https://medium.com/feed/@gi7w0rm) - [Google Project Zero Blog-Feed](https://googleprojectzero.blogspot.com/feeds/posts/default?alt=rss) - [Google Threat-Intelligence-Feed](https://feeds.feedburner.com/threatintelligence/pvexyqv7v0v) - [Google Threat Intelligence](https://cloud.google.com/blog/topics/threat-intelligence) - [Google Bedrohungsanalyse-Feed](https://blog.google/threat-analysis-group/rss/) - [Group-IB-Feed](https://blog.group-ib.com/rss.xml) - [HackerNews-Feed](https://feeds.feedburner.com/TheHackersNews) - [HarfangLab Lab-Feed](https://harfanglab.io/insidethelab/feed/) - [Hexacorn Blog-Feed](http://www.hexacorn.com/blog/feed/) - [Horizon3-Feed](https://www.horizon3.ai/feed/) - [hunt.io Blog](https://hunt.io/blog) - [Huntress Blog-Feed](https://www.huntress.com/blog/rss.xml) - [IC3 CSA-Feed](https://www.ic3.gov/CSA/rss) - [Infostealers Hub Nachrichten-Feed](https://www.infostealers.com/learn-info-stealers/feed/) - [infostealers Berichte-Feed](https://www.infostealers.com/info-stealers-reports/feed/) - [Intrinsec-Feed](https://www.intrinsec.com/feed/) - [isc sans edu Feed](https://isc.sans.edu/rssfeed.xml) - [JPCERT-Feed](https://blogs.jpcert.or.jp/en/atom.xml) - [JPCERT](https://www.jpcert.or.jp/english/) - [krebsonsecurity-Feed](https://krebsonsecurity.com/feed/) - [Malwarebytes Blog-Feed](https://www.malwarebytes.com/blog/feed/index.xml) - [MalwareTech-Feed](https://www.malwaretech.com/feed) - [Mauricio Velazco Blog](https://medium.com/@mvelazco) - [McAfee Labs-Feed](https://www.mcafee.com/blogs/other-blogs/mcafee-labs/feed/) - [Michael Haag Blog](https://haggis-m.medium.com/) - [Microsoft Security-Blog-Feed](https://www.microsoft.com/en-us/security/blog/feed/) - [Microsoft Incident-Response-Ninja-Hub](https://techcommunity.microsoft.com/blog/microsoftsecurityexperts/welcome-to-the-microsoft-incident-response-ninja-hub/4243594) - [Microsoft Threat-Intel-Feed](https://www.microsoft.com/en-us/security/blog/topic/threat-intelligence/feed) - [Morphisec Threat-Research](https://blog.morphisec.com/topic/threat-research) - [NCC Group Research-Feed](https://research.nccgroup.com/feed/) - [nccgroup Research-Blog Security](https://www.nccgroup.com/us/research-blog/?resource=18345&category=18146#hub) - [NCSC Nachrichten-Feed](https://feeds.english.ncsc.nl/news.rss) - [NIST-CVEs](https://nvd.nist.gov/vuln/search/results?isCpeNameSearch=false&results_type=overview&form_type=Basic&search_type=all&startIndex=0) - [NIST Cybersecurity-Insights-Feed](https://www.nist.gov/blogs/cybersecurity-insights/rss.xml) - [Offensive Research - DSAS by INJECT](https://blog.injectexp.dev/) - [Orange Cyberdefense Intel](https://www.orangecyberdefense.com/global/blog?tx_solr%5Bfilter%5D%5B0%5D=tags%3AIntelligence-led+Security) - [Outpost24 Research und Threat-Intel-Feed](https://outpost24.com/blog/category/research-and-threat-intel/feed/) - [Proofpoint Threat Insight](https://www.proofpoint.com/us/blog/threat-insight#) - [Qualys Threat-Research-Feed](https://blog.qualys.com/vulnerabilities-threat-research/feed) - [redcanary-Feed](https://www.redcanary.co/feed/) - [ReversingLabs Threat-Research](https://www.reversinglabs.com/blog/tag/threat-research) - [SANS Blog](https://www.sans.org/blog/) - [security.com Threat-Intel](https://www.security.com/threat-intelligence) - [SecurityAffairs APT-Feed](https://securityaffairs.com/category/apt/feed) - [SecurityWeek-Feed](https://www.securityweek.com/feed/) - [securlist APT-Zielangriffe-Feed](https://securelist.com/threat-category/apt-targeted-attacks/feed/) - [Sekoia Blog](https://blog.sekoia.io/) - [Sekoia Blog-Feed](https://blog.sekoia.io/feed/) - [SentinelOne Labs-Feed](https://www.sentinelone.com/labs/feed/) - [seqrite technischer Blog](https://www.seqrite.com/blog/category/technical/) - [Simone Kraus Blog-Feed](https://medium.com/feed/@simone.kraus) - [Sophos Threat-Research-Feed](https://news.sophos.com/en-us/category/threat-research/feed/) - [SpecterOps-Feed](https://posts.specterops.io/feed) - [Splunk Research-Blog](https://www.splunk.com/en_us/blog/author/secmrkt-research.html) - [Sybersecyrity Nachrichten-Feed](https://cybersecuritynews.com/feed/) - [Talos-Feed](https://feeds.feedburner.com/feedburner/Talos) - [Tenable-Blog](https://medium.com/tenable-techblog) - [The HackerNews-Feed](https://feeds.feedburner.com/TheHackersNews) - [thedfirreport-Feed](https://thedfirreport.com/feed/) - [ThreatConnect Blog-Feed](https://threatconnect.com/blog/feed/) - [ThreatLabz Zscaler-Blog](https://threatlabz.zscaler.com/blogs) - [Threatpost-Feed](https://threatpost.com/feed/) - [trendmicro Security-Feed](http://feeds.trendmicro.com/TrendMicroSimplySecurity) - [Trustwave Blog-Feed](https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/rss.xml) - [Twitter](https://twitter.com/home) - [Unit42-Feed](http://feeds.feedburner.com/Unit42) - [Unit42-Feed](https://unit42.paloaltonetworks.com/feed/) - [virusbulletin-Feed](https://www.virusbulletin.com/rss) - [virusbulletin](https://www.virusbulletin.com/virusbulletin/) - [Volexity Blog-Feed](https://www.volexity.com/blog/feed/) - [WeLiveSecurity-Feed](https://www.welivesecurity.com/en/rss/feed/) - [tl;dr sec Newsletter](https://tldrsec.com/)

📺 YouTube/Twitch-Kanäle

  • DFIR - 13cubed Videos
  • DFIR - SANS Videos
  • DFIR - MyDFIR
  • DFIR - DFIRScience
  • Malware-Analyse - jstrosch
  • Malware-Analyse - cyberraiju
  • Malware-Analyse - Botconf
  • DFIR - AntisyphonTraining
  • DFIR - BlackPerl
  • Malware-Analyse - malwareanalysisforhedgehogs
  • DFIR - BlueMonkey4n6
  • DFIR - binaryzone
  • Detection Engineering - Splunk - atomicsonafriday
  • Exploitation - HackerSploit
  • DFIR - TheTaggartInstitute
  • Malware-Analyse - JohnHammond
  • Malware-Analyse - invokereversing
  • Exploitation - Defcon Talks + https://media.defcon.org/
  • Exploitation - Alh4zr3d - twitch
  • Exploitation - Alh4zr3d - youtube
  • Exploitation - incodenito

🎙️ Podcasts

  • darknetdiaries
  • risky.biz
  • DFIR-Podcasts
  • cloud.withgoogle.com
  • Internet Storm Center SANS-Podcast
  • 7 Minuten Security-Podcast
  • hacking-humans
  • dayzerosec
  • CISO-Serie
  • Splunk Atomic on Friday
  • NolimitSecu (FR)
  • HacknSpeak (FR)
  • Radio CSIRT (FR)
  • DEV-Podcasts (FR)
  • Security Conversations
  • Monde de la cyber (FR)

💬 Discord-/Slack-Kanäle

  • RedTeam - 🔥 Initial Access Guild 🔥 Discord
  • RedTeam - 🔥 Red-Team VX community 🔥 Discord
  • RedTeam - BloodHoundHQ Slack
  • RedTeam - evilsocket Discord
  • RedTeam - OffSec Discord
  • Threat Hunting - Threat Hunter community Discord
  • PurpleTeam - Ipurpleteam Discord
  • Blueteam Detection engineering - Hunter's Den Discord
  • Blueteam Detection engineering - Sigma HQ Discord
  • Blueteam Threat Intel - Malcore Discord

📚 Training

DFIR

  • 13cubed - Untersuchung von Windows-Endpoints 13cubed.com - Windows-Endpoints

  • 13cubed - Untersuchung von Windows-Speicher 13cubed.com - Windows-Speicher

  • 13cubed - Untersuchung von Linux-Geräten 13cubed.com - Linux

  • SANS: FOR500

  • SANS: FOR508

  • Defensive Security: Linux-live-forensics

  • @0gtweet - Forensik-Kurs: Mastering Windows Forensics

  • @DebugPrivilege : Forensisches Debugging - kostenloser Kurs InsightEngineering

  • Challenges:

    • Arsenal Recon Disk-Images für DFIR: publicly-accessible-disk-images
    • @inversecos - APT-Emulations-Labs: xintra
    • @TheDFIRReport : Labs mit Logs aus den vorhandenen Berichten dfir-labs
    • @ACEresponder: Kurse mit detaillierten Erklärungen und Labs aceresponder.com
    • @binaryz0ne: DFIR-Challenges mit Datasets + Linux-Forensik-Workshop

SOC

📚 Bücher

DFIR

  • Practical Forensic Imaging
  • Practical-Linux-Forensics-Digital-Investigators
  • TheHitchhikersGuidetoDFIRExperiencesFromBeginnersandExperts - Kostenlos
  • Forensic Artifacts - Microsoft-Handbuch - kostenlos
  • Eric Zimmerman Tool-Handbücher - Kostenlos
  • The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory
  • Applied Incident Response
  • SANS FOR500 / FOR508-Buch
  • Blue Team Handbook: Incident Response Edition
  • Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software
  • Placing the Suspect Behind the Keyboard: DFIR Investigative Mindset
  • Crafting the InfoSec Playbook: Security Monitoring and Incident
  • Investigating Windows Systems#### Malware-Analyse
  • Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software

📚 Wissensseiten

  • DFIR - NTFS deepdive - ntfs.com
  • DFIR - aboutdfir
  • DFIR - Forensische Artefakte - Microsoft-Handbuch
  • Malware-Analyse - unprotect.it - Umgehungstechniken
  • Exploitation - hacktricks
  • Exploitation - PayloadsAllTheThings
  • Exploitation - red-team-note
  • Exploitation - Red Team Notes
  • DFIR - JPCERT-Tool-Analyse
  • Exploitation - Red Team TTP
  • Linux - EBPF-Dokumentation
  • DFIR - Microsoft NinjaHub
  • DEV - Windows-PInvoke-Signaturen
  • Datenschutz - VPN-Datenschutzleitfaden
  • Erkennung - GCP-Angriff - Verteidigung
  • Erkennung - Azure-Angriff-Verteidigung
  • Erkennung - Unprotect-Projekt
  • Exploitation - Hacker-Rezepte
  • Logs - Ereignis-IDs und andere - eventlog-compendium
  • Logs - Ereignis-IDs - ultimatewindowssecurity
  • Logs - Ereignis-IDs & Richtlinien - Microsoft

🧪 LAB

  • LAB-Automatisierung - ludus
  • LAB-Umgebung - Windows - GOAD
  • LAB-Automatisierung - warhorse
  • LAB-Automatisierung - Azure - BadZure
  • LAB-Automatisierung - Azure - AzureGoat
  • Betriebssystem - Malware-Analyse - flare-vm
  • Sandbox - cuckoo
  • Sandbox - CAPEv2
  • Sandbox - Malice (selbst gehosteter Virustotal-Klon)
  • Erkennungsplattform - wazuh
  • Erkennungsplattform - securityonion
  • Erkennungsplattform - Splunk
  • Erkennungsplattform - Elastic
  • Bereitstellung - ansible
  • SOC - Use-Case-Factory-Automatisierung - DetectIQ
  • Netzwerk-Logs - StratosphereLinuxIPS
  • Netzwerk-Logs - flare-fakenet-ng
  • Netzwerk-Logs - maltrail
  • Purpleteam - openbas
  • Honeypot - LLM-Honeypot galah
  • Honeypot - canary
  • Honeypot - opencanary

📦 Sonstiges

  • Crontab-Check
  • markmap.js.org (Markdown zu Mindmap)
  • Subnetzrechner
  • chmod-Rechner
  • Epoch-Zeitkonverter
  • cyberchef
  • Chrome-Add-on für TI-Überprüfungen
  • SMS-Verifizierung
  • Wegwerf-E-Mail
  • 10-Minuten-Mail

Inhaltserstellung

  • Angriffsanimations-Ersteller - aceresponder

🏷️ Lesezeichen

  • ⭐ Lesezeichen mit allen meinen Listen zum Importieren in deinen Browser (automatisch aktualisiert) Lesezeichen aktualisieren
Tool herunterladen
  • 🔢 Verdächtige MAC-Adressen: suspicious_mac_address_list.csv
  • 📛 Verdächtige Hostnamen: suspicious_hostnames_list.csv
  • 🌐 Verdächtige Browser-Erweiterungen: Browser-Erweiterungen
  • 📧 Microsoft-App-IDs-Liste - BEC-Erkennung microsoft_apps_list.csv
  • 🧮 Metadaten von Executables: executables_metadata_informations_list.csv
  • 🕸️ DNS-over-HTTPS-Serverliste: dns_over_https_servers_list.csv
  • 🕸️ Liste der Dynamic-DNS-Domains: dyndns_list.csv
  • 🪝 Phishing-Listen: Phishing-Domains und -URLs
  • 🕸️ Domains : [sinkholed servers]
  • 🕳️ Sinkholed Domains : sinkholed_domains.csv
  • 🕳️ Sinkholed-Website: SINKHOLED
  • 📚 Hijacklibs (automatisch aktualisiert): hijacklibs_list.csv
  • 🌐 TOR-Node-Listen (automatisch aktualisiert): [TOR]
  • 🛠️ LOLDriver-Liste (automatisch aktualisiert): loldrivers_only_hashes_list.csv
  • 🛠️ Liste schädlicher Bootloader (automatisch aktualisiert): malicious_bootloaders_only_hashes_list.csv
  • 📜 Liste schädlicher SSL-Zertifikate (automatisch aktualisiert): ssl_certificates_malicious_list.csv
  • 🖥️ RMM-Erkennung: [RMM]
  • 👤🔑 Wichtige Rollen, Gruppen und Berechtigungen für AD/EntraID/AWS/Graph: [permissions]
  • 💻🔒 Bekannte Ransomware-Dateierweiterungen: ransomware_extensions_list.csv
  • 💻🔒 Bekannte Ransomware-Dateinamen und Lösegeldnotizen: ransomware_notes_list.csv
  • 📝 Windows-ASR-Regeln: windows_asr_rules.csv
  • 🌐 DNSTWIST-Listen (automatisch aktualisiert): DNSTWIST-Standarddomains + Skript
  • 🌍 VPN IP-Adresslisten (automatisch aktualisiert):
    • 🛡️ NordVPN: nordvpn_ips_list.csv
    • 🛡️ ProtonVPN: protonvpn_ip_list.csv
    • 🛡️ SurfShark: surfshark_vpn_servers_domains_and_ips_list.csv
    • 🛡️ MullVad: mullvad_relay_servers_ips_list.csv
  • 🌍 Proxys PROXY-IP/Port-Listen
  • 🏢 Unternehmens-IP-Adressbereichslisten (automatisch aktualisiert): Standardlisten + Skript / Microsoft
  • 📍 GeoIP-Dienstlisten: ip_location_sites_list.csv
  • 🧬 Yara-Regeln: Threat-Hunting-Yara-Regeln
  • 🧬 Erkennungsmuster für offensive Tools: offensive_tool_keywords.csv
  • 🧬 Erkennungsmuster für Greyware-Tools: greyware_tool_keyword.csv
  • 🧬 AV-Signatur-Schlüsselwörter: signature_keyword.csv
  • 🧬 Microsoft Defender AV-Signaturlisten: [Defender] + yara
  • 🧬 ClamAV-Signaturlisten: [ClamAV]
  • 🔗 Weitere Korrelationslisten: [Others]
  • 🆔 Verdächtige VSCODE-Erweiterungslisten: vsxsentry
  • 🆔 Verdächtige Browser-Erweiterungslisten: extsentry
  • [Event-Parser] procmon-parser
  • [Event-Parser] Linux - MasterParser
  • [EVTX] Hayabusa
  • [EVTX] WELA
  • [EVTX] chainsaw
  • [EVTX] APTHunter
  • [EVTX / Auditd] Zircolite
  • werejugo
  • srum-dump
  • ADTimeline
  • PersistenceSniper
  • [O365] Logs - Microsoft-Analyzer-Suite
  • Logon Tracer
  • Timeline Plaso
  • Timeline TimeSketch
  • regripper
  • OneDrive-OCR-DB-Artefaktsammler (exe)
  • OneDrive-OCR-DB-Artefaktsammler (python)
  • hollows hunter
  • PE sieve
  • RdpCacheStitcher
  • Strings suchen - ripgrep
  • Strings suchen - Recoll
  • Kape
  • Kape Files
  • Weitere Kape-Ressourcen
  • VolatileDataCollector
  • Velociraptor
  • TZ-Tools
  • Nirsoft Tools
  • [Speicher] MemDump
  • [Speicher] MemProcFS
  • [Speicher] MemProcFS-Analyzer
  • [Speicher] avml
  • [Speicher] WinPmem
  • [Speicher] Volatility
  • [Image-Mount] FTK Imager
  • [Image-Mount] OSFMount
  • [Netzwerk] Network Miner
  • [Netzwerk] Wireshark
  • [Netzwerk] xplico
  • [Carving] PhotoRec
  • [Carving] Bulk Extractor
  • Didier Stevens Tools
  • [Speicher] Lime
  • Windows-Artefakte
  • [Linux] UAC
  • [Linux] EXT4 / XFS - fjta
  • Listen - aboutdfir.com
  • Monitoring - Osquery
  • [IR-Leitfaden] OpenProject
  • [OSX-Tools] Knockknock
  • [OSX-Tools] mac_apt
  • DNS-Forensik für Chrome-Browser-Erweiterungen
  • AVAST IOC
  • Zimperium IOC
  • HarfangLab IOC
  • DoctorWeb IOC
  • BlackLotusLab IOC
  • prodaft IOC
  • Pr0xylife DarkGate IOC
  • Pr0xylife Latrodectus IOC
  • Pr0xylife WikiLoader IOC
  • Pr0xylife SSLoad IOC
  • Pr0xylife Pikabot IOC
  • Pr0xylife Matanbuchus IOC
  • Pr0xylife QakBot IOC
  • Pr0xylife IceID IOC
  • Pr0xylife Emotet IOC
  • Pr0xylife BumbleBee IOC
  • Pr0xylife Gozi IOC
  • Pr0xylife NanoCore IOC
  • Pr0xylife NetWire IOC
  • Pr0xylife AsyncRAT IOC
  • Pr0xylife Lokibot IOC
  • Pr0xylife RemcosRAT IOC
  • Pr0xylife nworm IOC
  • Pr0xylife AZORult IOC
  • Pr0xylife NetSupportRAT IOC
  • Pr0xylife BitRAT IOC
  • Pr0xylife BazarLoader IOC
  • Pr0xylife SnakeKeylogger IOC
  • Pr0xylife njRat IOC
  • Pr0xylife Vidar IOC
  • Pr0xylife Warmcookie IOC
  • Cloud-Intel-IOCs
  • Phishing-URLs - Feed der letzten Woche
  • SpamHaus drop.txt
  • SpamHaus drop + ASN
  • UrlHaus_misp
  • UrlHaus_misp ASN
  • UrlHaus
  • vx-underground - Großartige Ressource für Samples und Intelligence-Berichte
  • Ransomware.live
  • rosti.bin-Feed öffentlicher Berichte
  • APTMAP
  • CVE-Schwachstellendatenbank
  • CVE-Schwachstellen-Framework
  • REACT-Framework
  • 🔥ALLE TI-Berichte🔥
  • 🔥ALLE TI-Berichtssuchen🔥
  • urldna.io
  • URL checkphish
  • ipvoid
  • mxtoolbox
  • mxtoolbox-Mail-Header
  • Microsoft TI
  • pulsedive
  • URL-Redirect-Checker
  • threatbook
  • Webarchiv
  • McAfee Threat Intelligence Exchange
  • Kaspersky Security Network
  • Microsoft Security Intelligence Report
  • IBM X-Force Exchange
  • AlienVault OTX
  • greynoise
  • whoxy
  • URL tiny-scan
  • Zertifikate - crt.sh
  • Website-Web-Check
  • validin.com
  • Browser-Erweiterungs-CRX-Checker
  • .EXE-Lookup - echotrail
  • Malware-Traffic-Analysis (PCAP-Dateien)
  • redhuntlabs
  • Whois-DomainTools
  • ASN-Check bgp.he
  • viewdns
  • OUI-MAC-Adressen-Lookup
  • macvendorlookup
  • .EXE-Lookup - xcyclopedia
  • abuse.ch
  • malware-traffic-analysis
  • waybackmachine
  • Online-Lookup für Paste-Tools
  • dnshistory
  • asnlookup
  • Browser-Erweiterungs-Checker - CRXaminer
  • ipinfo.io
  • fofa.info
  • SecurityTrail
  • ZommEye
  • BlueCoat-Lookup
  • Norton-Lookup
  • Fortinet-Lookup
  • McAfee-Lookup
  • Trellix-Lookup
  • Palo-Alto-Lookup
  • Talos-Intelligence-Lookup
  • Checkpoint-Lookup
  • Cyren-Lookup
  • Forcepoint-Lookup
  • Trend-Micro-Lookup
  • USB-&-PCI-Datenbank - DeviceHunt
  • unshorten it
  • urlunscrambler
  • URLEncode & Decode
  • longurl
  • Message-Header
  • MXToolbox-E-Mail-Header
  • E-Mail-Header-Analysator
  • E-Mail-Header-Analyse
  • GitLab-Dashboard aus Excel
  • uncoder
  • DeHashed
  • Diff-Checker
  • IT-Tools
  • ChatGPT
  • KQL-Hunting-Abfragen
  • Ressourcen für Detection Engineering
  • Defender-Ressource
  • awesome-threat-detection
  • LOLOLFarm
  • Exploitation - dayzerosec
  • Malware-Analyse - MalwareTechBlog
  • Malware-Analyse - radkawar
  • Exploitation - LiveOverflow
  • Malware-Analyse - neoeno
  • Malware-Analyse - AzakaSekai
  • CTI - bushidotoken
  • CTI - @TLP_R3D
  • Windows-Interna - @mrexodia
  • !!! Exploitation - ippsec
  • Exploitation - flangvik
  • Konferenz-Kanal - scrtinsomnihack
  • Konferenz-Kanal - OffensiveCon
  • Konferenz-Kanal - BSidesSF
  • Konferenz-Kanal - BSidesTLV
  • Konferenz-Kanal - bsidesbudapest
  • Konferenz-Kanal - SecuritybsidesOrgUk
  • Konferenz-Kanal - bsidescanberra9688
  • Konferenz-Kanal - brucontalks
  • Konferenz-Kanal - DEFCONConference
  • Konferenz-Kanal - Disobey
  • Konferenz-Kanal - hitbsecconf
  • Konferenz-Kanal - SANSOffensiveOperations
  • Konferenz-Kanal - BlackHillsInformationSecurity
  • Konferenz-Kanal - RITSEC
  • Konferenz-Kanal - Preludeorg
  • Konferenz-Kanal - BlackHatOfficialYT
  • Konferenz-Kanal - TROOPERScon
  • Konferenz-Site - infocon.org
  • Konferenz-Site - sectube.tv
  • Konferenz-Kanal - x33conf
    • tryhackme - SOC Level 1

    • tryHackme - SOC Level 2

    • letsdefend.io @chrissanders88 - letsdefend.io

    • Constructing Defense constructingdefense.com

    • SANS: SANS555

    • Xintra: Angriff und Verteidigung von Azure M365

    • Challenges:

      • Splunk Boss Of The SOC - BOTS
        • BOTS Datensatz v1
        • BOTS Datensatz v2
        • BOTS Datensatz v3
    • @TheDFIRReport : Labs mit Logs aus den vorhandenen Berichten dfir-labs

    • @ACEresponder: Kurse mit detaillierten Erklärungen und Labs aceresponder.com

    • @inversecos - APT-Emulations-Labs: xintra

    Offensive

    • OSCP - HTB
    • OSCP - Kurs PEN200
    • OSEP - Kurs PEN300

    Challenges

    • HackTheBox
    • Pentestlab
    • Root-Me
    • TryHackMe
    • Zenk-Security

    RE / Malware-Analyse / Deep Dive

    • OpenSecurityTraining2
    The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory
  • Evasive Malware: A Field Guide to Detecting, Analyzing, and Defeating Advanced Threats
  • SOC

    • Blue Team Handbook: SOC, SIEM, and Threat Hunting
    • BTFM: Blue Team Field Manual
    • PTFM: Purple Team Field Manual + PTFM: Purple Team Field Manual v2
    • EDR - Einführung in die Endpoint-Sicherheit
    • MITRE - 11 Strategies of a World-Class Cybersecurity Operations Center
    • Überblick über den Betrieb eines SOC - Modern SOC
    • Practical Malware Analysis: The Hands-On Guide to Dissecting Malicious Software
    • SANS-555-Buch

    Deep Dive

    • Windows Internals Bücher
    • How Linux Works
    • Linux Device Drivers
    • Understanding The Linux Virtual Memory Manager
    • Linux insides
    • Linux Ebpf
    • Windows Security Internals

    Exploitation

    • Hacking Art Exploitation
    • Hacker Playbook Practical Penetration Testing
    • RTFM: Red Team Field Manual
    • Red Team Development and Operations: A practical guide
    • RTRM: Red Team Reference Manual
    • POC||GTFO

    KI

    • Hands Machine Learning
  • Logs - Ereignis-IDs Anmeldetypen - Microsoft
  • Logs - Azure SigninLogs-Schema
  • Logs - Azure SigninLogs-Risikoerkennung
  • Logs - AADSTS-Fehlercodes
  • Logs - Microsoft-Fehlersuche
  • Logs - Microsoft-Entra-Authentifizierungs- und Autorisierungsfehlercodes
  • Logs - Microsoft Defender-Ereignis-IDs
  • Logs - Microsoft Defender for Cloud-Warnungsreferenzen
  • Logs - Microsoft Defender for Identity-Warnungsreferenzen
  • Logs - Microsoft Defender XDR-Schemas
  • Logs - Microsoft-DNS-Debug-Ereignis-IDs
  • Logs - Sysmon-Ereignis-IDs
  • weitere Cheatsheets
  • Exploitation - TLS-Details
  • SOC - E-Mail-Header IANA
  • SOC - DKIM, DMARC, SPF
  • SOC - Kerberos-Protokoll erklärt
  • SOC - ADSecurity-AD-Angriffe
  • SOC - Pass-the-Ticket erklärt
  • SOC - Kerberoasting erklärt
  • SOC - Kerberos-Unconstrained-Delegation erklärt
  • SOC - AS_REP-Roasting erklärt
  • SOC - Golden Tickets erklärt
  • SOC - Silver Ticket erklärt
  • SOC - Skeleton Key erklärt
  • SOC - NTLM-Relay erklärt
  • SOC - LLMNR-Poisoning erklärt
  • SOC - DCsync erklärt
  • SOC - DCShadow-Angriff erklärt
  • SOC - Interviewfragen von LetsDefend
  • SOC - Shell-Befehlsargumente erklärt
  • Honeypot - Respotter (Responder-Honeypot)
  • Honeypot - Certiception (ADCS-Honeypot)
  • Honeypot - cowrie
  • Maldev - Defense Evasion - avred
  • Maldev - Defense Evasion - gocheck
  • Aufklärung - HEDnsExtractor
  • Erkennungsagent - Sandfly Linux-Agent
  • Log-Weiterleitung - openwec (Windows-Ereignisweiterleitung)
  • Threat-Hunting-Plattform - deephunter
  • Windows-Logs - JonMon
  • Windows-Logs - Sysmon
  • Linux-Logs - ossec
  • Linux-Logs - ecapture (SSL/TLS)
  • Linux-Logs - tracee
  • Linux-Logs - auditd
  • Linux-Logs - SysmonForLinux
  • Linux-Logs - kunai
  • CTI - OpenCTI
  • CTI - MISP
  • Code-Analyse
  • IR-Plattform - iris-web
  • IR-Plattform - rAIdline
  • IR-Plattform - FIR
  • Herausforderungen - DFIR LABS
  • Log-Beispiele - Splunk Attack Range
  • IT - Remote-Verbindungsmanager - xpipe
  • Endpoint-Sicherheit - Windows-Härtung - Harden-Windows-Security
  • Endpoint-Sicherheit - Linux-Härtung - lynis
  • Endpoint-Sicherheit - Linux - apparmor