
NetScope
Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

A repository of sysmon configuration modules

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Detect Tactics, Techniques & Combat Threats

Collection of private Yara rules.

A repository to release detection rules to the public

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

Yara Rules for Modern Malware

Provides curated Sysmon event-tracing configuration templates for detecting Cobalt Strike, webshells, ransomware artifacts, and known exploit…

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

Runs custom filters on Elasticsearch and alerts on matches

Public repository of Sigma and YARA rules created by Synacktiv

Detection of Manjusaka C2 framework

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, Suricata and…