
threat-intel
This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.

Yara Rules for Modern Malware



Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

Slides from various conference talks

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

Elastic version of SOC prime watcher rules

This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

Slides and materials from conference presentations

Covered CVEs: CVE-2026-28755, CVE-2026-42926, CVE-2026-9256, CVE-2026-42055, CVE-2026-42533


A repository to release detection rules to the public

Defensive research repository for CVE-2025-55182 (Pre-Auth RCE in React Server Components/Next.js). Includes technical analysis, detection rules…

Free, offline SOC Analyst Hub for Tier 1 — IR checklists, alert triage playbooks, threat hunting queries & analyst onboarding. Single HTML file, no…

Sigma Rule for CVE-2025-49666
