
signatures
Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

The Sigma command line interface based on pySigma

Rules generated from our investigations.

Sigma rules from Joe Security

A repository to release detection rules to the public

Some Threat Hunting queries useful for blue teamers

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.

Slides and materials from conference presentations

Slides from various conference talks


TrustedSec Sysinternals Sysmon Community Guide

AV/EDR Lab environment setup references to help in Malware development

Yara Rules for Modern Malware

Sigma rules to share with the community

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research


Elastic version of SOC prime watcher rules