
Azure-Sentinel
Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

YARA signature and IOC database for my scanners and tools

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM


This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

Rules generated from our investigations.

The Sigma command line interface based on pySigma

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.

TrustedSec Sysinternals Sysmon Community Guide

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…


Slides and materials from conference presentations


Sigma Rule for CVE-2025-49666

Free, offline SOC Analyst Hub for Tier 1 — IR checklists, alert triage playbooks, threat hunting queries & analyst onboarding. Single HTML file, no…

CVE-2017-0144