
osquery
SQL powered operating system instrumentation, monitoring, and analytics.

SQL powered operating system instrumentation, monitoring, and analytics.

Arkime is an open source, large scale, full packet capturing, indexing, and database system.

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

A repository of sysmon configuration modules

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Detect Tactics, Techniques & Combat Threats

Spip network sensor written in Go

First public analysis of SoftLanding UEFI bootkit: Ring -2 implant, CVE-2025-7029, 240+ Gigabyte boards, GPU AI evasion, dual C2. YARA + Sigma +…

Mapping Corelight or Zeek data to Elastic Common Schema logs

Read-only WordPress plugin that scans for artifacts of the wp2shell exploit chain (CVE-2026-63030 / CVE-2026-60137)

Custom YARA rule for detecting artifacts of CVE-2025-32433, an Erlang/OTP SSH pre-authentication RCE vulnerability. Validated against public PoCs and…

Threat hunting command system for agentic IDEs

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.

Multi-Stage Attack Modeling and Detection of Log4Shell for CVE-2021-44228

Sigma Rule for CVE-2025-49666

Collection of private Yara rules.