SkillAgentSearch skills...

Awesome Threat Detection

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

Install / Use

npx skills add 0x4D31/awesome-threat-detection

Installs into whichever agent you are using.

About this skill

Quality Score

0/100

Supported Platforms

Universal

README

Awesome Threat Detection and Hunting

Awesome

A curated list of awesome threat detection and hunting resources

Contents

Tools

  • NRD-db - Automatically fetches and stores newly registered domains in a Redis database.
  • MITRE ATT&CK Navigator (source code) - The ATT&CK Navigator is designed to provide basic navigation and annotation of ATT&CK matrices, something that people are already doing today in tools like Excel.
  • HELK - A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities.
  • DetectionLab - Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices.
  • Revoke-Obfuscation - PowerShell Obfuscation Detection Framework.
  • Invoke-ATTACKAPI - A PowerShell script to interact with the MITRE ATT&CK Framework via its own API.
  • Unfetter - A reference implementation provides a framework for collecting events (process creation, network connections, Window Event Logs, etc.) from a client machine and performing CAR analytics to detect potential adversary activity.
  • Flare - An analytical framework for network traffic and behavioral analytics.
  • RedHunt-OS - A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment.
  • Oriana - Lateral movement and threat hunting tool for Windows environments built on Django comes Docker ready.
  • Bro-Osquery - Bro integration with osquery
  • Brosquery - A module for osquery to load Bro logs into tables
  • DeepBlueCLI - A PowerShell Module for Hunt Teaming via Windows Event Logs
  • Uncoder - An online translator for SIEM saved searches, filters, queries, API requests, correlation and Sigma rules
  • CimSweep - A suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows
  • Dispatch - An open-source crisis management orchestration framework
  • EQL - Event Query Language
    • EQLLib - The Event Query Language Analytics Library (eqllib) is a library of event based analytics, written in EQL to detect adversary behaviors identified in MITRE ATT&CK™.
  • BZAR (Bro/Zeek ATT&CK-based Analytics and Reporting) - A set of Zeek scripts to detect ATT&CK techniques
  • Security Onion - An open-source Linux distribution for threat hunting, security monitoring, and log management. It includes ELK, Snort, Suricata, Zeek, Wazuh, Sguil, and many other security tools
  • Varna - A quick & cheap AWS CloudTrail Monitoring with Event Query Language (EQL)
  • BinaryAlert - Serverless, real-time & retroactive malware detection
  • hollows_hunter - Scans all running processes, recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
  • ThreatHunting - A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
  • Sentinel Attack - A repository of Azure Sentinel alerts and hunting queries leveraging sysmon and the MITRE ATT&CK framework
  • Brim - A desktop application to efficiently search large packet captures and Zeek logs
  • Capa - An open-source tool to identify capabilities in executable files.
  • certgrep - A fast Certificate Transparency Log regex domain lookup tool.
  • Have I Been Squatted - A fast domain typosquatting detection tool.
  • Intel Owl - An Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale.
  • YARA - The pattern matching swiss knife
  • Splunk Security Content Splunk-curated detection content that can easily be used accross many SIEMs (see Uncoder Rule Converter.)
  • Threat Bus - Threat intelligence dissemination layer to connect security tools through a distributed publish/subscribe message broker.
  • VAST - A network telemetry engine for data-driven security investigations.
  • zeek2es - An open source tool to convert Zeek logs to Elastic/OpenSearch. You can also output pure JSON from Zeek's TSV logs!
  • LogSlash: A standard for reducing log volume without sacrificing analytical capability.
  • SOC-Multitool: A powerful and user-friendly browser extension that streamlines investigations for security professionals.
  • Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark.
  • ProcMon for Linux
  • Synthetic Adversarial Log Objects (SALO) - A framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event.

Detection, Alerting and Automation Platforms

Check out the Detection and Response Pipeline repository for more resources. The repo contains a compilation of suggested tools/services for each component in a detection and response pipeline, along with real-world examples. The purpose is to create a reference hub for designing effective threat detection and response pipelines.

  • ElastAlert - A framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch
  • StreamAlert - A serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define
  • Matano: An open source security lake platform (SIEM alternative) for threat hunting, detection and response on AWS. Matano lets you write advanced detections as code (using python) to correlate and alert on threats in realtime.
  • Shuffle: A general purpose security automation platform.
  • Sublime: An open platform for detection, response, and threat hunting in email environments. Sublime lets you write advanced detections as code to alert and remediate threats like phishing in real-time.
  • Substation - A cloud native data pipeline and transformation toolkit for security teams.

Endpoint Monitoring

  • osquery (github) - SQL powered operating system instrumentation, monitoring, and analytics
  • Kolide Fleet - A flexible control server for osquery fleets
  • Zeek Agent - An endpoint monitoring agent that provides host activity to Zeek
  • Velociraptor - Endpoint visibility and collection tool
  • Sysdig - A tool for deep Linux system visibility, with native support for containers. Think about sysdig as strace + tcpdump + htop + iftop + lsof + ...awesome sauce
  • go-audit - An alternative to the Linux auditd daemon
  • [Sysmon](https://doc

Related Skills

View on GitHub
GitHub Stars4.7k
CategoryDevelopment
Updated22h ago
Forks759

Security Score

85/100

Audited on Aug 7, 2026

No findings