Showing 35 of 71 projects
A lightweight Bash script for scanning Linux/Unix/OSX systems for Indicators of Compromise (IOCs) without installation.
A Python tool to analyze, explore, and revive malicious HTTP traffic from PCAP files for security research.
A curated collection of Event ID resources for digital forensics and incident response professionals.
A PowerShell suite for remote Windows incident response and hunting using CIM/WMI, requiring no agent deployment.
An open-source framework for detecting command and control communication through network traffic analysis using Zeek logs.
Open-source detection rules for identifying SolarWinds SunBurst backdoor activities and related vulnerabilities across multiple security tools.
A self-hosted incident response platform that automates alert handling and ticket management for security teams.
An open-source platform for collecting, processing, and analyzing forensic artifacts from macOS, Windows, and Linux systems.
A PowerShell module collection for agentless artifact gathering and reconnaissance on Windows endpoints.
A lightweight investigation notebook for security analysts to document and track threat intelligence.
A collection of prescriptive recipes for preparing and applying countermeasures against cyber threats and attacks.
A browser extension that streamlines security investigations by providing quick lookups for IPs, domains, hashes, and other indicators.
A curated list of tools and resources for understanding, detecting, and removing malware persistence techniques across operating systems.
A collection of Splunk SPL queries and prototypes for threat hunting and detection engineering.
A PowerShell module for remote endpoint threat hunting, scanning for indicators of compromise and collecting system state information.
A pub-sub broker for threat intelligence data that connects open-source security tools like OpenCTI, MISP, Zeek, and VAST.
A lightweight incident response tool for rapid suspicious file discovery during threat hunting and forensic triage.
A command-line tool for macOS persistence mechanism emulation and testing, designed for threat hunters.
A Python tool for advanced analysis of Windows AppCompat/AmCache forensic artifacts, enabling threat hunting beyond basic grep techniques.
A Python script that uses Volatility to analyze malware memory footprints by comparing Windows memory images before and after infection.
A curated collection of information and tools for detecting, analyzing, and hunting malware persistence mechanisms across operating systems.
Suricata rules for network anomaly detection and threat hunting.
A Python-based multithreaded threat intelligence gathering tool that collects, stores, and serves indicators of compromise from various sources.
An autonomous open-source security agent for Linux that detects, scores, and automatically responds to threats using eBPF, AI, and collaborative defense.
An open-source repository of cybersecurity detection rules and threat identifiers for security teams to enhance threat detection capabilities.
A collection of Splunk SPL queries for detecting vulnerability exploits, malware, and MITRE ATT&CK TTPs in security logs.
An open-source book providing SOC analysts and threat hunters with practical guidance on using Suricata for network security monitoring.
Jupyter notebooks and Python tools for threat hunting and data exploration with Suricata network security data.
A PowerShell module for targeted containment and remediation during incident response, enabling remote cleanup of malware artifacts.
A PowerShell module for interacting with the urlscan.io API to automate threat hunting and intelligence gathering.
A hybrid AI honeypot for detecting and interacting with mass web application exploitation attempts.
A collection of open-source threat detection rules for Snort, Sigma, and Yara security tools.
Automatically converts Sigma detection rules to Kusto Query Language (KQL) for Microsoft Defender and Sentinel.
Automates conversion of Sigma rules to Terraform and Sentinel YAML for detection engineering in Microsoft Sentinel.
Automatically converts Sigma detection rules into Splunk SPL queries for security monitoring and threat hunting.
Open-Awesome is built by the community, for the community. Submit a project, suggest an awesome list, or help improve the catalog on GitHub.