
awesome-threat-detection
Curated list of threat detection and hunting resources: detection rules, SIEM and log analysis tools, endpoint/network monitoring, datasets,…

Curated list of threat detection and hunting resources: detection rules, SIEM and log analysis tools, endpoint/network monitoring, datasets,…

A curated list of resources related to Industrial Control System (ICS) security.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Network anomaly detector that monitors raw packets to identify port scanning activity in real time, with flexible sniffing duration controls and live…

A host based IDS written in C# Targetted at Metasploit

Zeek script that monitors SMB traffic and alerts on known ransomware filenames using the Anti-Ransomware File System Resource Manager list.

Host IDS for desktop users

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

CY376 Blue Team project — pfSense DMZ, Suricata IDS/IPS, and automated host hardening against CVE-2014-6271

Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

🍯 T-Pot - The All In One Multi Honeypot Platform 🐝

Github mirror of official Kismet repository

Best Practice Auditd Configuration

A python2 script for sweeping a network to find windows systems compromised with the DOUBLEPULSAR implant.

Host-local Linux security orchestrator enforcing nftables policy with HIDS/HIPS telemetry, bounded threat-intelligence feeds, out-of-band WAAP log…

The Sigma command line interface based on pySigma

Capturing, analysing and responding to cyber attacks