Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Threat Detection

Threat Detection

129 projects

Showing 36 of 129 projects

Atomic Red Team
Atomic Red TeamC

A library of portable detection tests mapped to the MITRE ATT&CK framework for security testing.

#mitre#command-line-tools#detection-validation
Stars12.2k
Forks3.2k
Last commit1 day ago
Sigma Rules
Sigma RulesPython

A generic and open signature format for describing log event detections, shareable across SIEM systems.

#signatures#yaml#siem
Stars10.8k
Forks2.7k
Last commit1 day ago
Honeypots
HoneypotsPython

A curated list of awesome honeypot resources, tools, and related components for cybersecurity research and defense.

#honeypot#awesome-list#malware-analysis
Stars10.5k
Forks1.4k
Last commit1 month ago
YARA
YARAC

A pattern-matching tool for malware researchers to identify and classify malware samples using custom rules.

#yara-rules#pattern-matching#security-tools
Stars9.8k
Forks1.6k
Last commit7 days ago
Sysdig Falco
Sysdig FalcoC++

A cloud native runtime security tool for Linux that detects abnormal behavior and security threats in real-time.

#hacktoberfest#container-security#syscall-monitoring
Stars9.2k
Forks1.1k
Last commit4 days ago
Maltrail
MaltrailPython

A malicious traffic detection system that monitors network traffic for blacklisted threats and suspicious activities using public feeds and heuristics.

#sensor#blacklist-feeds#security
Stars8.6k
Forks1.3k
Last commit2 days ago
sysmon-config
sysmon-config

A high-quality, commented Sysmon configuration template for Windows system monitoring and incident investigation.

#netsec#sysinternals#windows-security
Stars5.6k
Forks1.9k
Last commit2 years ago
ThreatMapper
ThreatMapperTypeScript

Open source CNAPP that hunts for threats in cloud native platforms, ranks them by risk, and visualizes attack paths.

#container-security#vulnerability-management#compliance-scanning
Stars5.3k
Forks636
Last commit1 month ago
Awesome Threat Detection and Hunting
Awesome Threat Detection and Hunting

A curated list of awesome open-source tools, detection rules, datasets, and resources for threat detection and hunting.

#sigma-rules#awesome-list#security
Stars4.7k
Forks756
Last commit6 months ago
Awesome YARA
Awesome YARA

A curated list of awesome YARA rules, tools, and resources for malware researchers and security professionals.

#digital-forensics#yara-rules#yara-scanner
Stars4.2k
Forks552
Last commit1 month ago
LogonTracer
LogonTracerPython

A security tool that visualizes and analyzes Windows Active Directory event logs to investigate malicious logon activity.

#python-3#security-investigation#windows-event-log
Stars3.2k
Forks488
Last commit2 months ago
sysmon-modular
sysmon-modularPowerShell

A modular repository of Sysmon configuration modules for customizable endpoint detection and logging.

#modular#windows-security#endpoint-detection
Stars3.1k
Forks649
Last commit7 days ago
OpenCanary
OpenCanaryPython

A modular, low-resource network honeypot that mimics services to detect breaches and alert on attacker interactions.

#honeypot#python#intrusion-detection
Stars2.9k
Forks405
Last commit4 days ago
APTSimulator
APTSimulatorBatchfile

A Windows Batch script toolset that simulates Advanced Persistent Threat (APT) attack indicators to test security monitoring and detection capabilities.

#apt-simulation#red-team-tool#detection-validation
Stars2.8k
Forks452
Last commit
Elastic Detection Rules
Elastic Detection RulesPython

A public repository for developing, testing, and maintaining detection rules for Elastic Security's SIEM, with tools for Detections as Code.

#siem#security-automation#security
Stars2.7k
Forks684
Last commit1 day ago
Windows Events Attack Samples
Windows Events Attack SamplesHTML

A collection of 200 Windows EVTX event log samples mapped to MITRE ATT&CK techniques for detection testing and threat hunting.

#digital-forensics#security-training#windows-security
Stars2.6k
Forks433
Last commit
Fibratus
FibratusGo

A Windows security tool for real-time adversary tradecraft detection, memory scanning, and forensics via behavior-driven rules.

#rule-engine#windows-security#adversary
Stars2.5k
Forks218
Last commit1 day ago
Beelzebub
BeelzebubGo

A secure low-code honeypot framework that uses AI to create high-interaction decoy systems for cyber attack detection and analysis.

#honeypot#observability#low-code
Stars2.1k
Forks202
Last commit2 days ago
JA4+
JA4+Rust

A suite of network fingerprinting standards for TLS, TCP, HTTP, SSH, and other protocols to facilitate threat detection and security analysis.

#ja3-fingerprint#traffic-analysis#ja4-fingerprint
Stars2.0k
Forks179
Last commit1 month ago
Yara rules generator
Yara rules generatorPython

A Python tool that generates YARA rules for malware detection by filtering out strings and opcodes that appear in goodware.

#digital-forensics#python-tool#malwareanalysis
Stars1.8k
Forks305
Last commit6 months ago
Matano
MatanoRust

An open source, serverless security data lake for AWS that normalizes logs, enables detection-as-code, and supports petabyte-scale threat hunting.

#siem-alternative#aws-serverless#security-analytics
Stars1.7k
Forks122
Last commit1 year ago
Splunk Security Content
Splunk Security ContentPython

An open-source repository of security detections, analytic stories, and response playbooks mapped to MITRE ATT&CK for Splunk Enterprise Security.

#splunk-enterprise-security#security-analytics#cicd
Stars1.7k
Forks477
Last commit
SELKS
SELKSShell

A Linux distribution for network detection and response (NDR) built around Suricata, providing a complete NDR platform.

#iso-builder#suricata#ids
Stars1.6k
Forks290
Last commit10 months ago
Elastic Yara Signatures
Elastic Yara SignaturesYARA

Open-source detection logic (rules, YARA, ransomware protection) for Elastic Security's endpoint protection platform.

#malware-protection#yara-rules#open-security
Stars1.5k
Forks165
Last commit
Elastic Endpoint Behavioral Rules
Elastic Endpoint Behavioral RulesYARA

Open-source detection logic (rules, YARA, EQL) for Elastic Security's endpoint protection against malware, ransomware, and advanced threats.

#malware-protection#yara-rules#open-security
Stars1.5k
Forks165
Last commit
Joy
JoyC

A libpcap-based package for extracting and analyzing network flow data in JSON format for security research and monitoring.

#network-research#libpcap#json-output
Stars1.4k
Forks333
Last commit2 years ago
Network Flight Simulator (flightsim)
Network Flight Simulator (flightsim)Go

A lightweight utility to generate malicious network traffic patterns for evaluating security controls and network visibility.

#c2-traffic#malware-simulation#command-line-tool
Stars1.4k
Forks145
Last commit
Honeytrap
HoneytrapGo

An extensible open-source framework for running, monitoring, and managing honeypots to detect and analyze cyber threats.

#honeypot#splunk#kafka
Stars1.3k
Forks180
Last commit2 years ago
Detection Engineering
Detection Engineering

A curated list of resources, tools, and frameworks for detection engineering in cybersecurity.

#mitre#security-analytics#siem
Stars1.3k
Forks135
Last commit10 days ago
Harden Runner GitHub Action
Harden Runner GitHub ActionTypeScript

A CI/CD security agent that monitors GitHub Actions runners for threats like network egress, file integrity, and process activity.

#supply-chain-security#actions#runners
Stars1.2k
Forks108
Last commit14 days ago
CertSpotter
CertSpotterGo

A lightweight Certificate Transparency log monitor that alerts you when SSL/TLS certificates are issued for your domains.

#ssl-monitoring#x509#certificate-transparency
Stars1.2k
Forks101
Last commit1 day ago
Red Team Automation (RTA)
Red Team Automation (RTA)Python

A framework of Python scripts for blue teams to test detection capabilities against malicious tradecraft modeled after MITRE ATT&CK.

#detection-validation#mitre-attack#cybersecurity
Stars1.1k
Forks219
Last commit7 years ago
Artillery
ArtilleryPython

An open-source blue team tool that protects Linux and Windows systems via honeypots, monitoring, and alerting.

#honeypot#windows-security#alerting-system
Stars1.0k
Forks204
Last commit4 years ago
Alerting and Detection Strategies (ADS) Framework | Palantir
Alerting and Detection Strategies (ADS) Framework | Palantir

A framework for developing rigorous, documented alerting and detection strategies to improve incident response efficacy.

#peer-review#security#mitre-attack
Stars890
Forks138
Last commit10 months ago
Apache Metron (incubating)
Apache Metron (incubating)Java

A centralized platform for security monitoring and analysis, integrating big data technologies for log aggregation, threat detection, and behavioral analytics.

#stream-processing#security-analytics#behavioral-analytics
Stars870
Forks503
Last commit
Zircolite
ZircolitePython

A standalone Python tool for applying SIGMA detection rules to EVTX, Auditd, Sysmon for Linux, and other log formats.

#sigma-rules#security#python3
Stars833
Forks114
Last commit1 month ago
Page 1 of 4

Related Tags

Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub
10 months ago
3 years ago
2 days ago
4 days ago
4 days ago
2 years ago
11 months ago
Next
#Network Security43
#Cybersecurity41
#Honeypot40
#Incident Response32
#Security30
#Security Monitoring29
#Intrusion Detection29
#Python27
#Security Tools25
#Malware Analysis22
#Docker14
#Threat Hunting14