
Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

I regularly update most of these lists after each tool i analyze in my detection keywords project
13cubed - Investigating Windows Endpoints 13cubed.com -windows endpoints
13cubed - Investigating Windows Memory 13cubed.com -windows memory
13cubed - Investigating Linux Devices 13cubed.com - linux
SANS: FOR500
SANS: FOR508
Defensive-security: Linux-live-forensics
@0gtweet - Forensic course: Mastering Windows Forensics
@DebugPrivilege : Forensic Debugging free course InsightEngineering
Challenges:
tryhackme - SOC lvl 1
tryHackme - SOC lvl 2
letsdefend.io @chrissanders88 - letsdefend.io
Constructing Defense constructingdefense.com
SANS: SANS555
Challenges:
@TheDFIRReport : LABs with logs from the existing reports dfir-labs
@ACEresponder: Courses with Detailed Explanations and Labs aceresponder.com
@inversecos - APT Emulation Labs: xintra