
Zeek-Intelligence-Feeds
Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Sigma rules from Joe Security

A repository to release detection rules to the public

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

A home for detection content developed by the delivr.to team

Some Threat Hunting queries useful for blue teamers

Default Detections for EDR

Purpleteam scripts simulation & Detection - trigger events for SOC detections

ETW based POC to identify direct and indirect syscalls

This repository contains supplemental items including IOCs, and signatures discussed in Huntress blogposts, and other media.

Small tool to play with IOCs caused by Imageload events

Detection rule validation

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

Slides and materials from conference presentations

Slides from various conference talks

This page is a result of the ongoing hands-on research around advanced Linux attacks, detection and forensics techniques and tools.

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)