MISP (core software) - Open Source Threat Intelligence and Sharing Platform
-
Updated
Apr 11, 2026 - PHP
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.
Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation
Sysmon configuration file template with default high-quality event tracing
✨ A curated list of awesome threat detection and hunting resources 🕵️♂️
Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.
IntelOwl: manage your Threat Intelligence at scale
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
754 structured cybersecurity skills for AI agents · Mapped to 5 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND & NIST AI RMF · agentskills.io standard · Works with Claude Code, GitHub Copilot, Codex CLI, Cursor, Gemini CLI & 20+ platforms · 26 security domains · Apache 2.0
A curated list of awesome YARA rules, tools, and people.
The Hunting ELK
Malwoverview is a first response tool for threat hunting across VirusTotal, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, IPInfo, Shodan, AbuseIPDB, GreyNoise, URLScan.io, Whois/RDAP, NIST, and VulnCheck. Supports LLM enrichment, IOC extraction, YARA scanning, and Android analysis.
Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Real-time HTTP Intrusion Detection
A repository of sysmon configuration modules
Interesting APT Report Collection And Some Special IOCs
YARA signature and IOC database for my scanners and tools
Windows Events Attack Samples
Add a description, image, and links to the threat-hunting topic page so that developers can more easily learn about it.
To associate your repository with the threat-hunting topic, visit your repo's landing page and select "manage topics."