
agentic-threat-hunting-framework
ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.

MCP to help Defenders Detection Engineer Harder and Smarter

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

Deploy web honeypots to capture emerging attack data, analyze ModSecurity audit logs via ELK, and share threat intelligence with MISP for…

This project is a SIEM with SIRP and Threat Intel, all in one.

PA Toolkit is a collection of traffic analysis plugins focused on security

threatspec - continuous threat modeling, through code

The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research the…

Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.

Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.

Windows-based C2 research tool that uses Spotify playlists as a command channel and Telegram for output delivery, demonstrating cloud-assisted…

CVE2PoC is a tool that helps penetration testers, bug hunters, and security researchers quickly find public exploits or PoCs related to a CVE ID

A verified map of reverse engineering and malware analysis. Disassemblers, unpacking, exploit dev, fuzzing, DFIR, and the deep-cut writeups other…

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…


A python package for use in generating fake data for SOC and security automation.

An Open Harness and Benchmark for AI in Cybersecurity Operations.