
100_days_of_kql_2026
A repo to hold KQL queries as part of my 100 days of KQL effort.
Tools for consuming, aggregating, and analyzing external threat intelligence feeds from various sources.

A repo to hold KQL queries as part of my 100 days of KQL effort.

OSINT intelligence on any IP, domain, or ASN

Red Hat security advisories

Dynamically generated Suricata rules from real-time threat feeds

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

A high-performance TAXII (Trusted Automated eXchange of Indicator Information) server written in Rust.

🦅 ZeroScout: The Autonomous Local & Cloud Threat Hunter. Visualize attacks in a live War Room, identify APT groups via Genetic Analysis, and…

Debian Security Tracker

Forked from https://gitlab.alpinelinux.org/kaniini/secfixes-tracker

Cyber Threat Intelligence (CTI) usando fontes e indicadores de ameaças nacionais, ou até globais, mas com evidencias ou indicadores nacionais do…

Collect VEX documents and update VEX Hub

This is the home of the Expel Intel Team. Here, we will share IOCs and other information that is either not suitable for fitting into other mediums…

Security advisories from Aqua Security

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

A lightweight Python module to interact with the [MITRE ATT&CK®](https://attack.mitre.org/) Enterprise dataset. Built for speed with minimal…

CLI client for abuse.ch