Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
awesome-threat-detection — Curated list of threat detection and hunting resources: detection rules, SIEM and log analysis tools, endpoint/network monitoring, datasets, trainings, labs. | Kitploit
Tools/GitHubGitHub/0x4d31/awesome-threat-detection
Network SecurityThreat IntelligenceIntrusion DetectionPapers & ResearchLearning & EducationIncident ResponseCurated ResourcesLearning Paths & CoursesLog Analysis

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Labs & Practice
Top in Curated Resources #17
Top in Learning Paths & Courses #19
Top in Papers & Research #20
GitHub0x4d31/awesome-threat-detection

awesome-threat-detection

Curated list of threat detection and hunting resources: detection rules, SIEM and log analysis tools, endpoint/network monitoring, datasets, trainings, labs.

View RepositoryWebsite
4.7k762629 months agoReviewed by Kitploit
Share

Awesome Threat Detection and Hunting

Awesome

A curated list of awesome threat detection and hunting resources

Contents

  • Threat Detection and Hunting
    • 🔨 Tools
      • Detection, Alerting and Automation Platforms
      • Endpoint Monitoring
      • Network Monitoring
      • Email Monitoring
    • 🔍 Detection Rules
    • 📑 Dataset
    • 📘 Resources
      • Frameworks
      • Windows
      • MacOS
      • Osquery
      • DNS
      • Fingerprinting
      • Data Science
      • Research Papers
      • Blogs
      • Related Awesome Lists
    • 🎙️ Podcasts
    • 🗞️ Newsletters
    • 🎥 Videos
    • 👩‍🎓 Trainings
    • 👩‍💻 Labs
    • 🤖 Twitter
  • Threat Simulation
    • 🪓 Tools
    • 📕 Resources
  • Contribute
  • License

Tools

  • NRD-db - Automatically fetches and stores newly registered domains in a Redis database.
  • MITRE ATT&CK Navigator (source code) - The ATT&CK Navigator is designed to provide basic navigation and annotation of ATT&CK matrices, something that people are already doing today in tools like Excel.
  • HELK - A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities.
  • DetectionLab - Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices.
  • Revoke-Obfuscation - PowerShell Obfuscation Detection Framework.
  • Invoke-ATTACKAPI - A PowerShell script to interact with the MITRE ATT&CK Framework via its own API.
  • Unfetter - A reference implementation provides a framework for collecting events (process creation, network connections, Window Event Logs, etc.) from a client machine and performing CAR analytics to detect potential adversary activity.
  • Flare - An analytical framework for network traffic and behavioral analytics.
  • RedHunt-OS - A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment.
  • Oriana - Lateral movement and threat hunting tool for Windows environments built on Django comes Docker ready.
  • Bro-Osquery - Bro integration with osquery
  • Brosquery - A module for osquery to load Bro logs into tables
  • DeepBlueCLI - A PowerShell Module for Hunt Teaming via Windows Event Logs
  • Uncoder - An online translator for SIEM saved searches, filters, queries, API requests, correlation and Sigma rules
  • CimSweep - A suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows
  • Dispatch - An open-source crisis management orchestration framework
  • EQL - Event Query Language
    • EQLLib - The Event Query Language Analytics Library (eqllib) is a library of event based analytics, written in EQL to detect adversary behaviors identified in MITRE ATT&CK™.
  • BZAR (Bro/Zeek ATT&CK-based Analytics and Reporting) - A set of Zeek scripts to detect ATT&CK techniques
  • Security Onion - An open-source Linux distribution for threat hunting, security monitoring, and log management. It includes ELK, Snort, Suricata, Zeek, Wazuh, Sguil, and many other security tools
  • Varna - A quick & cheap AWS CloudTrail Monitoring with Event Query Language (EQL)
  • BinaryAlert - Serverless, real-time & retroactive malware detection
  • hollows_hunter - Scans all running processes, recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
  • ThreatHunting - A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
  • Sentinel Attack - A repository of Azure Sentinel alerts and hunting queries leveraging sysmon and the MITRE ATT&CK framework
  • Brim - A desktop application to efficiently search large packet captures and Zeek logs
  • Capa - An open-source tool to identify capabilities in executable files.
  • certgrep - A fast Certificate Transparency Log regex domain lookup tool.
  • Have I Been Squatted - A fast domain typosquatting detection tool.
  • Intel Owl - An Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale.
  • YARA - The pattern matching swiss knife
  • Splunk Security Content Splunk-curated detection content that can easily be used accross many SIEMs (see Uncoder Rule Converter.)
  • Threat Bus - Threat intelligence dissemination layer to connect security tools through a distributed publish/subscribe message broker.
  • VAST - A network telemetry engine for data-driven security investigations.
  • zeek2es - An open source tool to convert Zeek logs to Elastic/OpenSearch. You can also output pure JSON from Zeek's TSV logs!
  • LogSlash: A standard for reducing log volume without sacrificing analytical capability.
  • SOC-Multitool: A powerful and user-friendly browser extension that streamlines investigations for security professionals.
  • Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark.
  • ProcMon for Linux
  • Synthetic Adversarial Log Objects (SALO) - A framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event.

Detection, Alerting and Automation Platforms

Download Tool