Open-Awesome
CategoriesAlternativesStacksSelf-HostedExplore
Open-Awesome

© 2026 Open-Awesome. Curated for the developer elite.

TermsPrivacyAboutGitHubRSS
  1. Home
  2. Tags
  3. Threat Hunting

Threat Hunting

72 projects

Showing 36 of 72 projects

Academic Resources and Grey Literature List
Academic Resources and Grey Literature List

A curated list of amazingly awesome open source intelligence (OSINT) tools and resources for cyber threat intelligence and investigations.

#social-media-analysis#data-breach#cyber-threat-intelligence
Stars27.6k
Forks3.8k
Last commit4 days ago
Sigma Rules
Sigma RulesPython

A generic and open signature format for describing log event detections, shareable across SIEM systems.

#signatures#yaml#siem
Stars10.8k
Forks2.7k
Last commit3 days ago
Sigma
SigmaPython

A generic and open signature format for describing log event detections, shareable across SIEM systems.

#signatures#yaml#siem
Stars10.8k
Forks2.7k
Last commit3 days ago
Awesome Incident Response
Awesome Incident Response

A curated list of tools and resources for digital forensics and incident response (DFIR) teams.

#digital-forensics#incident-response-tooling#awesome-list
Stars9.3k
Forks1.7k
Last commit8 days ago
Incident Response
Incident Response

A curated list of tools and resources for digital forensics and incident response (DFIR) teams.

#digital-forensics#security-automation#incident-response-tooling
Stars9.3k
Forks1.7k
Last commit8 days ago
MISP
MISPPHP

An open-source platform for collecting, storing, sharing, and acting upon cybersecurity threat intelligence and indicators.

#threat-sharing#security#fraud-management
Stars6.4k
Forks1.6k
Last commit1 day ago
dnstwist
dnstwistPython

Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation.

#python-tool#dns-analysis#osint
Stars5.7k
Forks849
Last commit1 year ago
sysmon-config
sysmon-config

A high-quality, commented Sysmon configuration template for Windows system monitoring and incident investigation.

#netsec#sysinternals#windows-security
Stars5.6k
Forks1.9k
Last commit2 years ago
Awesome Threat Detection and Hunting
Awesome Threat Detection and Hunting

A curated list of awesome open-source tools, detection rules, datasets, and resources for threat detection and hunting.

#sigma-rules#awesome-list#security
Stars4.7k
Forks760
Last commit6 months ago
ThreatHunter-Playbook
ThreatHunter-PlaybookPython

A community-driven open-source project that structures threat hunting workflows using MITRE ATT&CK, Jupyter notebooks, and AI-augmented planning.

#hunting-framework#mitre#community-driven
Stars4.6k
Forks858
Last commit6 months ago
Awesome YARA
Awesome YARA

A curated list of awesome YARA rules, tools, and resources for malware researchers and security professionals.

#digital-forensics#yara-rules#yara-scanner
Stars4.2k
Forks553
Last commit1 month ago
Hunting ELK (HELK)
Hunting ELK (HELK)Jupyter Notebook

An open-source threat hunting platform with advanced analytics capabilities built on ELK stack, Apache Spark, and Jupyter notebooks.

#apache-spark#elk-stack#security-analytics
Stars3.9k
Forks690
Last commit2 years ago
LOKI
LOKIPython

A simple IOC and YARA scanner for detecting malware and security threats via file names, hashes, YARA rules, and C2 connections.

#signature#hash#yara-rules
Stars3.8k
Forks615
Last commit6 months ago
Chainsaw
ChainsawRust

A fast, standalone tool for rapid threat hunting and forensic analysis of Windows event logs and other forensic artefacts.

#digital-forensics#sigma-rules#forensic-timeline
Stars3.6k
Forks300
Last commit4 days ago
Hayabusa
HayabusaRust

A Sigma-based threat hunting and fast forensics timeline generator for Windows event logs, written in Rust.

#digital-forensics#threat#sigma-rules
Stars3.3k
Forks285
Last commit1 day ago
Cyber Security University
Cyber Security University

A curated list of free, hands-on educational resources for learning cybersecurity through practical exercises and CTF challenges.

#digital-forensics#education#hands-on-learning
Stars3.2k
Forks303
Last commit11 months ago
Security Onion
Security Onion

A Linux distribution for threat hunting, enterprise security monitoring, and log management.

#enterprise-security#siem#ids
Stars3.1k
Forks526
Last commit5 years ago
sysmon-modular
sysmon-modularPowerShell

A modular repository of Sysmon configuration modules for customizable endpoint detection and logging.

#modular#windows-security#endpoint-detection
Stars3.1k
Forks651
Last commit10 days ago
PowerUpSQL
PowerUpSQLPowerShell

A PowerShell toolkit for attacking, auditing, and securing Microsoft SQL Server environments during penetration tests.

#windows-security#red-teaming#sql-server
Stars2.7k
Forks474
Last commit1 year ago
FireEye's Red Team Tool Countermeasures
FireEye's Red Team Tool CountermeasuresYARA

Snort and YARA rules to detect attacks using FireEye's red team tools, released after their 2020 breach disclosure.

#yara-rules#clamav#security-detection
Stars2.7k
Forks827
Last commit2 years ago
Elastic Detection Rules
Elastic Detection RulesPython

A public repository for developing, testing, and maintaining detection rules for Elastic Security's SIEM, with tools for Detections as Code.

#siem#security-automation#security
Stars2.7k
Forks684
Last commit12 hours ago
Windows Events Attack Samples
Windows Events Attack SamplesHTML

A collection of 200 Windows EVTX event log samples mapped to MITRE ATT&CK techniques for detection testing and threat hunting.

#digital-forensics#security-training#windows-security
Stars2.6k
Forks434
Last commit3 years ago
DeepBlueCLI
DeepBlueCLIPowerShell

A PowerShell module for threat hunting and detecting malicious activity via Windows Event Logs.

#command-line-auditing#security-forensics#detection-rules
Stars2.4k
Forks376
Last commit2 years ago
PersistenceSniper
PersistenceSniperPowerShell

A PowerShell module for Blue Teams, Incident Responders, and System Administrators to hunt persistence techniques implanted in Windows machines.

#windows-security#malware-detection#malware-analysis
Stars2.1k
Forks223
Last commit1 year ago
YETI
YETIPython

A forensics intelligence platform that bridges CTI and DFIR by storing threat intelligence and enabling bulk observable searches and threat-focused analysis.

#digital-forensics#enrichment#dfir-automation
Stars2.0k
Forks319
Last commit1 day ago
OSX Collector
OSX CollectorPython

A forensic evidence collection and analysis toolkit for macOS, gathering system data to investigate potential infections.

#forensic-collection#digital-forensics#system-investigation
Stars1.9k
Forks240
Last commit7 years ago
KQL Advanced Hunting Queries & Analytics Rules
KQL Advanced Hunting Queries & Analytics RulesPython

A collection of ready-to-use KQL queries for threat hunting, detection, and analytics in Microsoft Defender for Endpoint and Azure Sentinel.

#azure-sentinel#security-analytics#vulnerability-management
Stars1.7k
Forks325
Last commit15 hours ago
Matano
MatanoRust

An open source, serverless security data lake for AWS that normalizes logs, enables detection-as-code, and supports petabyte-scale threat hunting.

#siem-alternative#aws-serverless#security-analytics
Stars1.7k
Forks122
Last commit1 year ago
Malware Archive
Malware ArchiveHTML

A collection of real-world malware samples, analysis exercises, and training resources for cybersecurity education and research.

#maldoc-templates#lokibot#malware-samples
Stars1.7k
Forks241
Last commit2 years ago
Kansa
KansaPowerShell

A modular PowerShell framework for enterprise incident response and breach hunting using remote data collection.

#windows-api#enterprise-security#security-automation
Stars1.7k
Forks276
Last commit3 years ago
APT Hunter
APT HunterPython

A threat hunting tool that analyzes Windows event logs to detect APT movements and suspicious activity using pre-defined rules and statistical analysis.

#python-tool#sigma-rules#python3
Stars1.4k
Forks246
Last commit1 year ago
RedHunt OS
RedHunt OS

A pre-configured Linux virtual machine for adversary emulation and threat hunting with attacker and defender toolkits.

#osint#penetration-testing#virtual-machine
Stars1.3k
Forks200
Last commit1 year ago
Detection Engineering
Detection Engineering

A curated list of resources, tools, and frameworks for detection engineering in cybersecurity.

#mitre#security-analytics#siem
Stars1.3k
Forks139
Last commit1 day ago
Artic Wolf Labs
Artic Wolf Labs

A curated, vendor-neutral collection of free annual cybersecurity analysis and survey reports from trusted sources.

#reporting#security-reports#research-aggregation
Stars1.1k
Forks138
Last commit13 hours ago
Annual Security Reports
Annual Security Reports

A curated, vendor-neutral collection of free annual cybersecurity analysis and survey reports from trusted sources.

#reporting#security-reports#awesome-list
Stars1.1k
Forks138
Last commit13 hours ago
CobaltStrikeScan
CobaltStrikeScanC#

Scans files and process memory for Cobalt Strike beacons and extracts their configuration.

#cobalt-strike#windows-security#security-analysis
Stars921
Forks115
Last commit4 years ago
Page 1 of 2Next

Related Tags

#Incident Response44#Cybersecurity30#Threat Intelligence18#Security Operations17#Digital Forensics17#Dfir15#Security14#Mitre Attack14#Malware Analysis14#Threat Detection14#Sigma Rules12#Forensics11
Community-curated · Updated weekly · 100% open source

Found a gem we're missing?

Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.

Submit a projectStar on GitHub