
auditd-attack
A Linux Auditd rule set mapped to MITRE's Attack Framework
configuration-auditingdefensive-toolsintrusion-detection+2
824

A Linux Auditd rule set mapped to MITRE's Attack Framework

Parses public sandbox detonation reports to produce threat hunting intelligence, organizes findings via MITRE ATT&CK, assembles IOCs, and generates…

Automater - IP URL and MD5 OSINT Analysis

Clusters and elements to attach to MISP events or attributes (like threat actors)

IoCs and detection rules for the Notepad++ supply chain attack (CVE-2025-15556) — Lotus Blossom APT, June–December 2025. Includes Falcon LogScale…

Trust & Safety tools for working together to fight digital harms.

STIX 2.1 collections of the MITRE ATT&CK knowledge base, providing adversary tactics and techniques for enterprise, mobile, and ICS threat…