Awesome Threat Detection and Hunting

A curated list of awesome threat detection and hunting resources
Contents
- NRD-db - Automatically fetches and stores newly registered domains in a Redis database.
- MITRE ATT&CK Navigator (source code) - The ATT&CK Navigator is designed to provide basic navigation and annotation of ATT&CK matrices, something that people are already doing today in tools like Excel.
- HELK - A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities.
- DetectionLab - Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices.
- Revoke-Obfuscation - PowerShell Obfuscation Detection Framework.
- Invoke-ATTACKAPI - A PowerShell script to interact with the MITRE ATT&CK Framework via its own API.
- Unfetter - A reference implementation provides a framework for collecting events (process creation, network connections, Window Event Logs, etc.) from a client machine and performing CAR analytics to detect potential adversary activity.
- Flare - An analytical framework for network traffic and behavioral analytics.
- RedHunt-OS - A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment.
- Oriana - Lateral movement and threat hunting tool for Windows environments built on Django comes Docker ready.
- Bro-Osquery - Bro integration with osquery
- Brosquery - A module for osquery to load Bro logs into tables
- DeepBlueCLI - A PowerShell Module for Hunt Teaming via Windows Event Logs
- Uncoder - An online translator for SIEM saved searches, filters, queries, API requests, correlation and Sigma rules
- CimSweep - A suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows
- Dispatch - An open-source crisis management orchestration framework
- EQL - Event Query Language
- EQLLib - The Event Query Language Analytics Library (eqllib) is a library of event based analytics, written in EQL to detect adversary behaviors identified in MITRE ATT&CK™.
- BZAR (Bro/Zeek ATT&CK-based Analytics and Reporting) - A set of Zeek scripts to detect ATT&CK techniques
- Security Onion - An open-source Linux distribution for threat hunting, security monitoring, and log management. It includes ELK, Snort, Suricata, Zeek, Wazuh, Sguil, and many other security tools
- Varna - A quick & cheap AWS CloudTrail Monitoring with Event Query Language (EQL)
- BinaryAlert - Serverless, real-time & retroactive malware detection
- hollows_hunter - Scans all running processes, recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
- ThreatHunting - A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
- Sentinel Attack - A repository of Azure Sentinel alerts and hunting queries leveraging sysmon and the MITRE ATT&CK framework
- Brim - A desktop application to efficiently search large packet captures and Zeek logs
- Capa - An open-source tool to identify capabilities in executable files.
- certgrep - A fast Certificate Transparency Log regex domain lookup tool.
- Have I Been Squatted - A fast domain typosquatting detection tool.
- Intel Owl - An Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale.
- YARA - The pattern matching swiss knife
- Splunk Security Content Splunk-curated detection content that can easily be used accross many SIEMs (see Uncoder Rule Converter.)
- Threat Bus - Threat intelligence dissemination layer to connect security tools through a distributed publish/subscribe message broker.
- VAST - A network telemetry engine for data-driven security investigations.
- zeek2es - An open source tool to convert Zeek logs to Elastic/OpenSearch. You can also output pure JSON from Zeek's TSV logs!
- LogSlash: A standard for reducing log volume without sacrificing analytical capability.
- SOC-Multitool: A powerful and user-friendly browser extension that streamlines investigations for security professionals.
- Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark.
- ProcMon for Linux
- Synthetic Adversarial Log Objects (SALO) - A framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event.