
drovorub-hunt
A tool to assist with network-based hunting for GRU's Drovorub malware c2

A tool to assist with network-based hunting for GRU's Drovorub malware c2

Real-time malicious traffic detection system using public blacklists, static malware trails, and heuristic analysis to identify threats across DNS,…

Open-source IDS/IPS and WAF engine that analyzes logs and HTTP requests to detect and block malicious IPs, leveraging a crowdsourced community…

A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat intelligence.

A Linux Auditd rule set mapped to MITRE's Attack Framework

Curated Intelligence is working with analysts from around the world to provide useful information to organisations in Ukraine looking for additional…

Self-hosted dark web OSINT platform. Automated threat intelligence from query to graph in 13 steps. Free alternative to Recorded Future, DarkOwl, and…

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

An advanced real time threat intelligence framework to identify threats and malicious web traffic on the basis of IP reputation and historical data.

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

A repo to hold KQL queries as part of my 100 days of KQL effort.

Collection of IoCs available and related to attacks on ESXi infrastructures that occurred as of Friday February 3, 2023.

DugganUSA threat-intelligence contributions to the IETF Hackathon — real-world agentic-attack benchmark vectors, CVE-2026-33697 attestation analysis,…

High-speed Windows forensic triage platform that orchestrates the Hayabusa engine to transform raw EVTX logs into prioritized threat timelines with…

A lightweight Python module to interact with the [MITRE ATT&CK®](https://attack.mitre.org/) Enterprise dataset. Built for speed with minimal…

Vulnerability triage with provenance. Resolves CVEs from locally built corpora (NVD/KEV/EPSS, ExploitDB, nmap script.db) and emits verification…

Scalable threat intelligence platform that enriches observables and files using 200+ analyzers, with built-in GUI, REST API, and automated workflows…