
ThreatHunting-Keywords
Awesome list of keywords and artifacts for Threat Hunting sessions
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Awesome list of keywords and artifacts for Threat Hunting sessions

Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux

Kvasir: Penetration Test Data Management

Execution-Layer Security (ELS) for AI agents — policy-enforced shell with audit.

A wireshark plugin to instrument ETW

Rules generated from our investigations.

psad: Intrusion Detection and Log Analysis with iptables

Zeek Log Cheatsheets

This project is a SIEM with SIRP and Threat Intel, all in one.

Universal mobile devtool for Agents & Humans - control iOS Simulators, Android Emulators, and real devices from a single dashboard and CLI

This repository contains a list of new remediation scripts.

Powerful open-source CLI to audit security, costs, and best practices in AWS. 🩺 ☁️

The OWASP SecureTea Project provides a one-stop security solution for various devices (personal computers / servers / IoT devices)

Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event…

PowerShell module for Office 365 and Azure log collection

Searches For Threat Hunting and Security Analytics

Find phishing kits which use your brand/organization's files and image.

PCRE RegEx matching Log4Shell CVE-2021-44228 IOC in your logs