{"id":13409403,"url":"https://github.com/0x4D31/awesome-threat-detection","last_synced_at":"2025-03-14T14:31:20.768Z","repository":{"id":39633846,"uuid":"117328645","full_name":"0x4D31/awesome-threat-detection","owner":"0x4D31","description":"✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️","archived":false,"fork":false,"pushed_at":"2024-02-20T09:53:21.000Z","size":50013,"stargazers_count":3383,"open_issues_count":17,"forks_count":611,"subscribers_count":189,"default_branch":"master","last_synced_at":"2024-05-23T04:13:16.912Z","etag":null,"topics":["awesome","awesome-list","detection","incident-response","security","threat-detection","threat-hunting"],"latest_commit_sha":null,"homepage":"https://0x4d31.github.io/awesome-threat-detection/","language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/0x4D31.png","metadata":{"files":{"readme":"README.html","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":null,"code_of_conduct":"CODE-OF-CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null}},"created_at":"2018-01-13T08:50:29.000Z","updated_at":"2024-05-22T03:20:52.000Z","dependencies_parsed_at":"2024-01-10T02:34:33.273Z","dependency_job_id":"9f810ab4-274d-476d-a427-6a09b524856c","html_url":"https://github.com/0x4D31/awesome-threat-detection","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0x4D31%2Fawesome-threat-detection","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0x4D31%2Fawesome-threat-detection/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0x4D31%2Fawesome-threat-detection/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/0x4D31%2Fawesome-threat-detection/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/0x4D31","download_url":"https://codeload.github.com/0x4D31/awesome-threat-detection/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":243593379,"owners_count":20316176,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["awesome","awesome-list","detection","incident-response","security","threat-detection","threat-hunting"],"created_at":"2024-07-30T20:01:00.508Z","updated_at":"2025-03-14T14:31:15.756Z","avatar_url":"https://github.com/0x4D31.png","language":null,"funding_links":[],"categories":["Other Awesome Lists","Others","Other Lists","AWESOME LISTS","Uncategorized","Security","Others (1002)","Related Awesome Lists","Foundation Models, LLMs, and Agents","awesome-list","七、实用资源补充","网站外链","安全监控","Other Awesome Security Lists","Security monitoring","Threat Intelligence"],"sub_categories":["Other Security Awesome Lists","Detection Resources","Uncategorized","📡 Detection Resources","Alignment, Safety, Security, and Trustworthiness","3. 其他精选Awesome列表","隐私相关领域法规/条例","威胁狩猎","Cloud","Threat hunting","Penetration Testing Report Templates"],"readme":"\n      \u003chtml\u003e\n        \u003chead\u003e\n          \u003ctitle\u003eAwesome Threat Detection and Hunting\u003c/title\u003e\n          \u003cmeta name=\"viewport\" content=\"width=device-width, initial-scale=1\"\u003e\n          \u003cmeta charset=\"UTF-8\"\u003e\n        \u003c/head\u003e\n        \u003cbody\u003e\n          \u003cdiv id='content'\u003e\n      \u003ch1 id=\"awesome-threat-detection-and-hunting\"\u003eAwesome Threat Detection and Hunting\u003c/h1\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/sindresorhus/awesome\"\u003e\u003cimg src=\"https://cdn.rawgit.com/sindresorhus/awesome/d7305f38d29fed78fa85652e3a63e154dd8e8829/media/badge.svg\" alt=\"Awesome\" /\u003e\u003c/a\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n  \u003cp\u003eA curated list of awesome threat detection and hunting resources\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2 id=\"contents\"\u003eContents\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eThreat Detection and Hunting\u003c/li\u003e\u003cul\u003e\n\u003cli\u003e🔨 \u003ca href=\"#tools\"\u003eTools\u003c/a\u003e\u003cul\u003e\n\u003cli\u003e\u003ca href=\"#detection-alerting-and-automation-platforms\"\u003eDetection, Alerting and Automation Platforms\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#endpoint-monitoring\"\u003eEndpoint Monitoring\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#network-monitoring\"\u003eNetwork Monitoring\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#email-monitoring\"\u003eEmail Monitoring\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e🔍 \u003ca href=\"#detection-rules\"\u003eDetection Rules\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📑 \u003ca href=\"#dataset\"\u003eDataset\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📘 \u003ca href=\"#resources\"\u003eResources\u003c/a\u003e\u003cul\u003e\n\u003cli\u003e\u003ca href=\"#frameworks\"\u003eFrameworks\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#windows\"\u003eWindows\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#macos\"\u003eMacOS\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#osquery\"\u003eOsquery\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#dns\"\u003eDNS\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#fingerprinting\"\u003eFingerprinting\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#data-science\"\u003eData Science\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"research-papers\"\u003eResearch Papers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#blogs\"\u003eBlogs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#related-awesome-lists\"\u003eRelated Awesome Lists\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e🎙️ \u003ca href=\"#podcasts\"\u003ePodcasts\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🗞️ \u003ca href=\"#newsletters\"\u003eNewsletters\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🎥 \u003ca href=\"#videos\"\u003eVideos\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e👩‍🎓 \u003ca href=\"#trainings\"\u003eTrainings\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e👩‍💻 \u003ca href=\"#labs\"\u003eLabs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e🤖 \u003ca href=\"#twitter\"\u003eTwitter\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\n\u003cli\u003eThreat Simulation\u003c/li\u003e\u003cul\u003e\n\u003cli\u003e🪓 \u003ca href=\"#threat-simulation-tools\"\u003eTools\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e📕 \u003ca href=\"#threat-simulation-resources\"\u003eResources\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\n\u003cli\u003e\u003ca href=\"#contribute\"\u003eContribute\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"#license\"\u003eLicense\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"tools\"\u003eTools\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://mitre.github.io/attack-navigator/enterprise/\"\u003eMITRE ATT\u0026CK Navigator\u003c/a\u003e (\u003ca href=\"https://github.com/mitre-attack/attack-navigator\"\u003esource code\u003c/a\u003e) - The ATT\u0026amp;CK Navigator is designed to provide basic navigation and annotation of ATT\u0026amp;CK matrices, something that people are already doing today in tools like Excel.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Cyb3rWard0g/HELK\"\u003eHELK\u003c/a\u003e - A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/clong/DetectionLab/\"\u003eDetectionLab\u003c/a\u003e - Vagrant \u0026amp; Packer scripts to build a lab environment complete with security tooling and logging best practices.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/danielbohannon/Revoke-Obfuscation\"\u003eRevoke-Obfuscation\u003c/a\u003e - PowerShell Obfuscation Detection Framework.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Cyb3rWard0g/Invoke-ATTACKAPI\"\u003eInvoke-ATTACKAPI\u003c/a\u003e - A PowerShell script to interact with the MITRE ATT\u0026amp;CK Framework via its own API.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/unfetter-analytic/unfetter\"\u003eUnfetter\u003c/a\u003e - A reference implementation provides a framework for collecting events (process creation, network connections, Window Event Logs, etc.) from a client machine and performing CAR analytics to detect potential adversary activity.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/austin-taylor/flare\"\u003eFlare\u003c/a\u003e - An analytical framework for network traffic and behavioral analytics.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/redhuntlabs/RedHunt-OS\"\u003eRedHunt-OS\u003c/a\u003e - A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mvelazc0/Oriana\"\u003eOriana\u003c/a\u003e - Lateral movement and threat hunting tool for Windows environments built on Django comes Docker ready.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bro/bro-osquery\"\u003eBro-Osquery\u003c/a\u003e - Bro integration with osquery\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jandre/brosquery\"\u003eBrosquery\u003c/a\u003e - A module for osquery to load Bro logs into tables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sans-blue-team/DeepBlueCLI\"\u003eDeepBlueCLI\u003c/a\u003e - A PowerShell Module for Hunt Teaming via Windows Event Logs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://uncoder.io\"\u003eUncoder\u003c/a\u003e - An online translator for SIEM saved searches, filters, queries, API requests, correlation and Sigma rules\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PowerShellMafia/CimSweep\"\u003eCimSweep\u003c/a\u003e - A suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Netflix/dispatch\"\u003eDispatch\u003c/a\u003e - An open-source crisis management orchestration framework\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/endgameinc/eql\"\u003eEQL\u003c/a\u003e - Event Query Language\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/endgameinc/eqllib\"\u003eEQLLib\u003c/a\u003e - The Event Query Language Analytics Library (eqllib) is a library of event based analytics, written in EQL to detect adversary behaviors identified in MITRE ATT\u0026amp;CK™.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mitre-attack/bzar\"\u003eBZAR\u003c/a\u003e (Bro/Zeek ATT\u0026amp;CK-based Analytics and Reporting) - A set of Zeek scripts to detect ATT\u0026amp;CK techniques\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Security-Onion-Solutions/security-onion\"\u003eSecurity Onion\u003c/a\u003e - An open-source Linux distribution for threat hunting, security monitoring, and log management. It includes ELK, Snort, Suricata, Zeek, Wazuh, Sguil, and many other security tools\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/endgameinc/varna\"\u003eVarna\u003c/a\u003e - A quick \u0026amp; cheap AWS CloudTrail Monitoring with Event Query Language (EQL)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/airbnb/binaryalert\"\u003eBinaryAlert\u003c/a\u003e - Serverless, real-time \u0026amp; retroactive malware detection\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hasherezade/hollows_hunter\"\u003ehollows_hunter\u003c/a\u003e - Scans all running processes, recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/olafhartong/ThreatHunting\"\u003eThreatHunting\u003c/a\u003e - A Splunk app mapped to MITRE ATT\u0026amp;CK to guide your threat hunts\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/BlueTeamLabs/sentinel-attack\"\u003eSentinel Attack\u003c/a\u003e - A repository of Azure Sentinel alerts and hunting queries leveraging sysmon and the MITRE ATT\u0026amp;CK framework\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/brimsec/brim\"\u003eBrim\u003c/a\u003e - A desktop application to efficiently search large packet captures and Zeek logs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/virustotal/yara\"\u003eYARA\u003c/a\u003e - The pattern matching swiss knife\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/intelowlproject/IntelOwl\"\u003eIntel Owl\u003c/a\u003e - An Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/fireeye/capa\"\u003eCapa\u003c/a\u003e - An open-source tool to identify capabilities in executable files.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/splunk/security_content\"\u003eSplunk Security Content\u003c/a\u003e Splunk-curated detection content that can easily be used accross many SIEMs (see Uncoder Rule Converter.)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tenzir/threatbus\"\u003eThreat Bus\u003c/a\u003e - Threat intelligence dissemination layer to connect security tools through a distributed publish/subscribe message broker.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tenzir/vast\"\u003eVAST\u003c/a\u003e - A network telemetry engine for data-driven security investigations.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/corelight/zeek2es\"\u003ezeek2es\u003c/a\u003e - An open source tool to convert Zeek logs to Elastic/OpenSearch.  You can also output pure JSON from Zeek's TSV logs!\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FoxIO-LLC/LogSlash\"\u003eLogSlash\u003c/a\u003e: A standard for reducing log volume without sacrificing analytical capability.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zdhenard42/SOC-Multitool\"\u003eSOC-Multitool\u003c/a\u003e: A powerful and user-friendly browser extension that streamlines investigations for security professionals.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SuperCowPowers/zat\"\u003eZeek Analysis Tools (ZAT)\u003c/a\u003e: Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sysinternals/ProcMon-for-Linux\"\u003eProcMon for Linux\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/splunk/salo\"\u003eSynthetic Adversarial Log Objects (SALO)\u003c/a\u003e - A framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"detection-alerting-and-automation-platforms\"\u003eDetection, Alerting and Automation Platforms\u003c/h3\u003e\n\u003cblockquote\u003e\n  \u003cp\u003eCheck out the \u003ca href=\"https://github.com/0x4D31/detection-and-response-pipeline\"\u003eDetection and Response Pipeline\u003c/a\u003e repository for more resources. The repo contains a compilation of suggested tools/services for each component in a detection and response pipeline, along with real-world examples. The purpose is to create a reference hub for designing effective threat detection and response pipelines.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Yelp/elastalert\"\u003eElastAlert\u003c/a\u003e - A framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/airbnb/streamalert\"\u003eStreamAlert\u003c/a\u003e - A serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/matanolabs/matano\"\u003eMatano\u003c/a\u003e: An open source security lake platform (SIEM alternative) for threat hunting, detection and response on AWS. Matano lets you write advanced detections as code (using python) to correlate and alert on threats in realtime.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Shuffle/Shuffle\"\u003eShuffle\u003c/a\u003e: A general purpose security automation platform.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sublime-security/sublime-platform\"\u003eSublime\u003c/a\u003e: An open platform for detection, response, and threat hunting in email environments. Sublime lets you write advanced detections as code to alert and remediate threats like phishing in real-time.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/brexhq/substation\"\u003eSubstation\u003c/a\u003e - A cloud native data pipeline and transformation toolkit for security teams.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"endpoint-monitoring\"\u003eEndpoint Monitoring\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://osquery.io\"\u003eosquery\u003c/a\u003e (\u003ca href=\"https://github.com/osquery/osquery\"\u003egithub\u003c/a\u003e) - SQL powered operating system instrumentation, monitoring, and analytics\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kolide/fleet\"\u003eKolide Fleet\u003c/a\u003e - A flexible control server for osquery fleets\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zeek/zeek-agent\"\u003eZeek Agent\u003c/a\u003e - An endpoint monitoring agent that provides host activity to Zeek\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Velocidex/velociraptor\"\u003eVelociraptor\u003c/a\u003e - Endpoint visibility and collection tool\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/draios/sysdig\"\u003eSysdig\u003c/a\u003e - A tool for deep Linux system visibility, with native support for containers. Think about sysdig as strace + tcpdump + htop + iftop + lsof + …awesome sauce\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/slackhq/go-audit\"\u003ego-audit\u003c/a\u003e - An alternative to the Linux auditd daemon\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://docs.microsoft.com/en-us/sysinternals/downloads/sysmon\"\u003eSysmon\u003c/a\u003e - A Windows system service and device driver that monitors and logs system activity to the Windows event log\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Sysinternals/SysmonForLinux\"\u003eSysmon for Linux\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ossec/ossec-hids\"\u003eOSSEC\u003c/a\u003e - An open-source Host-based Intrusion Detection System (HIDS)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/wazuh/wazuh\"\u003eWAZUH\u003c/a\u003e - An open-source security platform\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"configuration\"\u003eConfiguration\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MHaggis/sysmon-dfir\"\u003esysmon-DFIR\u003c/a\u003e - Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SwiftOnSecurity/sysmon-config\"\u003esysmon-config\u003c/a\u003e - Sysmon configuration file template with default high-quality event tracing.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/olafhartong/sysmon-modular\"\u003esysmon-modular\u003c/a\u003e - A repository of sysmon configuration modules. It also includes a \u003ca href=\"https://github.com/olafhartong/sysmon-modular/blob/master/attack_matrix/README.md\"\u003emapping\u003c/a\u003e of Sysmon configurations to MITRE ATT\u0026amp;CK techniques.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Neo23x0/auditd\"\u003eauditd configuration\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/palantir/osquery-configuration\"\u003eosquery-configuration\u003c/a\u003e - A repository for using osquery for incident detection and response.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"network-monitoring\"\u003eNetwork Monitoring\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zeek/zeek\"\u003eZeek\u003c/a\u003e (formerly Bro) - A network security monitoring tool\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ntop/ntopng\"\u003entopng\u003c/a\u003e - A web-based network traffic monitoring tool\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://suricata-ids.org\"\u003eSuricata\u003c/a\u003e - A network threat detection engine\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://snort.org\"\u003eSnort\u003c/a\u003e (\u003ca href=\"https://github.com/snort3/snort3\"\u003egithub\u003c/a\u003e) - A network intrusion detection tool\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cisco/joy\"\u003eJoy\u003c/a\u003e - A package for capturing and analyzing network flow data and intraflow data, for network research, forensics, and security monitoring\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/dreadl0ck/netcap\"\u003eNetcap\u003c/a\u003e - A framework for secure and scalable network traffic analysis\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/aol/moloch\"\u003eMoloch\u003c/a\u003e - A large scale and open source full packet capture and search tool\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/google/stenographer\"\u003eStenographer\u003c/a\u003e - A full-packet-capture tool\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"fingerprinting-tools\"\u003eFingerprinting Tools\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/salesforce/ja3\"\u003eJA3\u003c/a\u003e - A method for profiling SSL/TLS Clients and Servers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/salesforce/hassh\"\u003eHASSH\u003c/a\u003e - Profiling Method for SSH Clients and Servers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yahoo/rdfp\"\u003eRDFP\u003c/a\u003e - Zeek Remote desktop fingerprinting script based on \u003ca href=\"https://github.com/0x4D31/fatt\"\u003eFATT\u003c/a\u003e (Fingerprint All The Things)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/0x4D31/fatt\"\u003eFATT\u003c/a\u003e - A pyshark based script for extracting network metadata and fingerprints from pcap files and live network traffic\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/LeeBrotherston/tls-fingerprinting\"\u003eFingerprinTLS\u003c/a\u003e - A TLS fingerprinting method\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cisco/mercury\"\u003eMercury\u003c/a\u003e - Network fingerprinting and packet metadata capture\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/salesforce/GQUIC_Protocol_Analyzer\"\u003eGQUIC Protocol Analyzer for Zeek\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rapid7/recog\"\u003eRecog\u003c/a\u003e - A framework for identifying products, services, operating systems, and hardware by matching fingerprints against data returned from various network probes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/CERT-Polska/hfinger\"\u003eHfinger\u003c/a\u003e - Fingerprinting HTTP requests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/salesforce/jarm\"\u003eJARM\u003c/a\u003e - An active Transport Layer Security (TLS) server fingerprinting tool.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"email-monitoring\"\u003eEmail Monitoring\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sublime-security/sublime-platform\"\u003eSublime Platform\u003c/a\u003e - An email threat detection engine\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"detection-rules\"\u003eDetection Rules\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SigmaHQ/sigma\"\u003eSigma\u003c/a\u003e - Generic Signature Format for SIEM Systems\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://research.splunk.com/detections/\"\u003eSplunk Detections\u003c/a\u003e and \u003ca href=\"https://research.splunk.com/stories/\"\u003eAnalytic stories\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/elastic/detection-rules\"\u003eElastic Detection Rules\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://car.mitre.org/\"\u003eMITRE CAR\u003c/a\u003e - The Cyber Analytics Repository is a knowledge base of analytics developed by MITRE based on the Adversary Tactics, Techniques, and Common Knowledge (ATT\u0026amp;CK™) adversary model.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/InQuest/awesome-yara#rules\"\u003eAwesome YARA Rules\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/chronicle/detection-rules\"\u003eChronicle Detection Rules\u003c/a\u003e - Collection of YARA-L 2.0 sample rules for the Chronicle Detection API.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/GoogleCloudPlatform/security-analytics\"\u003eGCP Security Analytics\u003c/a\u003e - Community Security Analytics provides a set of community-driven audit \u0026amp; threat queries for Google Cloud.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sublime-security/sublime-rules\"\u003eSublime Detection Rules\u003c/a\u003e - Email attack detection, response, and hunting rules.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"dataset\"\u003eDataset\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Cyb3rWard0g/mordor\"\u003eMordor\u003c/a\u003e - Pre-recorded security events generated by simulated adversarial techniques in the form of JavaScript Object Notation (JSON) files. The data is categorized by platforms, adversary groups, tactics and techniques defined by the Mitre ATT\u0026amp;CK Framework.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.secrepo.com\"\u003eSecRepo.com\u003c/a\u003e(\u003ca href=\"https://github.com/sooshie/secrepo\"\u003egithub repo\u003c/a\u003e) - Samples of security related data.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/splunk/botsv1\"\u003eBoss of the SOC (BOTS) Dataset Version 1\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/splunk/botsv2\"\u003eBoss of the SOC (BOTS) Dataset Version 2\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/splunk/botsv3\"\u003eBoss of the SOC (BOTS) Dataset Version 3\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/endgameinc/ember\"\u003eEMBER\u003c/a\u003e (\u003ca href=\"https://arxiv.org/abs/1804.04637\"\u003epaper\u003c/a\u003e) - The EMBER dataset is a collection of features from PE files that serve as a benchmark dataset for researchers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ytisf/theZoo\"\u003etheZoo\u003c/a\u003e - A repository of LIVE malwares\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.unb.ca/cic/datasets/index.html\"\u003eCIC Datasets\u003c/a\u003e - Canadian Institute for Cybersecurity datasets\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.netresec.com/?page=PcapFiles\"\u003eNetresec's PCAP repo list\u003c/a\u003e - A list of public packet capture repositories, which are freely available on the Internet.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbousseaden/PCAP-ATTACK\"\u003ePCAP-ATTACK\u003c/a\u003e - A repo of PCAP samples for different ATT\u0026amp;CK techniques.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbousseaden/EVTX-ATTACK-SAMPLES\"\u003eEVTX-ATTACK-SAMPLES\u003c/a\u003e - A repo of Windows event samples (EVTX) associated with ATT\u0026amp;CK techniques (\u003ca href=\"https://docs.google.com/spreadsheets/d/12V5T9j6Fi3JSmMpAsMwovnWqRFKzzI9l2iXS5dEsnrs/edit#gid=164587082\"\u003eEVTX-ATT\u0026CK Sheet\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://log-sharing.dreamhosters.com\"\u003ePublic Security Log Sharing Site\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/splunk/attack_data\"\u003eattack_data\u003c/a\u003e - A repository of curated datasets from various attacks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"resources\"\u003eResources\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"docs/huntpedia.pdf\"\u003eHuntpedia\u003c/a\u003e - Your Threat Hunting Knowledge Compendium\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"docs/hunt-evil.pdf\"\u003eHunt Evil\u003c/a\u003e - Your Practical Guide to Threat Hunting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"docs/The-Hunters-Handbook.pdf\"\u003eThe Hunter's Handbook\u003c/a\u003e - Endgame's guide to adversary hunting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Cyb3rWard0g/ThreatHunter-Playbook\"\u003eThreatHunter-Playbook\u003c/a\u003e - A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ThreatHuntingProject/ThreatHunting\"\u003eThe ThreatHunting Project\u003c/a\u003e - A great \u003ca href=\"https://github.com/ThreatHuntingProject/ThreatHunting/tree/master/hunts\"\u003ecollection of hunts\u003c/a\u003e and threat hunting resources.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/A3sal0n/CyberThreatHunting\"\u003eCyberThreatHunting\u003c/a\u003e - A collection of resources for threat hunters.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/MHaggis/hunt-detect-prevent\"\u003eHunt-Detect-Prevent\u003c/a\u003e - Lists of sources and utilities to hunt, detect and prevent evildoers.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/@palantir/alerting-and-detection-strategy-framework-52dc33722df2\"\u003eAlerting and Detection Strategy Framework\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.sans.org/reading-room/whitepapers/threats/generating-hypotheses-successful-threat-hunting-37172\"\u003eGenerating Hypotheses for Successful Threat Hunting\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Foundstone/ExpertInvestigationGuides/tree/master/ThreatHunting\"\u003eExpert Investigation Guide - Threat Hunting\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://adsecurity.org/wp-content/uploads/2017/04/2017-BSidesCharm-DetectingtheElusive-ActiveDirectoryThreatHunting-Final.pdf\"\u003eActive Directory Threat Hunting\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.countercept.com/our-thinking/threat-hunting-for-fileless-malware/\"\u003eThreat Hunting for Fileless Malware\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://blog.jpcert.or.jp/.s/2016/01/windows-commands-abused-by-attackers.html\"\u003eWindows Commands Abused by Attackers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/0x4D31/deception-as-detection\"\u003eDeception-as-Detection\u003c/a\u003e - Deception based detection techniques mapped to the MITRE’s ATT\u0026amp;CK framework.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://ryanstillions.blogspot.com.au/2014/04/on-ttps.html\"\u003eOn TTPs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHunting On The Cheap (\u003ca href=\"https://www.sans.org/cyber-security-summit/archives/file/summit-archive-1492182404.pdf\"\u003eSlides\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.cyberhuntz.com/2016/08/threat-hunting-techniques-av-proxy-dns.html\"\u003eThreat Hunting Techniques - AV, Proxy, DNS and HTTP Logs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://pleasefeedthegeek.wordpress.com/2012/12/20/detecting-malware-beacons-using-splunk/\"\u003eDetecting Malware Beacons Using Splunk\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://www.austintaylor.io/network/traffic/threat/data/science/hunting/funnel/machine/learning/domain/expertise/2017/07/11/data-science-hunting-funnel/\"\u003eData Science Hunting Funnel\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://www.austintaylor.io/d3/python/pandas/2016/02/01/create-d3-chart-python-force-directed/\"\u003eUse Python \u0026 Pandas to Create a D3 Force Directed Network Diagram\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://slack.engineering/syscall-auditing-at-scale-e6a3ca8ac1b8\"\u003eSyscall Auditing at Scale\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://summitroute.com/blog/2016/12/25/Catching_attackers_with_go-audit_and_a_logging_pipeline/\"\u003eCatching attackers with go-audit and a logging pipeline\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://summitroute.com/blog/2015/06/10/the_conventry_conundrum_of_threat_intelligence/\"\u003eThe Coventry Conundrum of Threat Intelligence\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.pwc.co.uk/issues/cyber-security-data-privacy/research/signal-att-and-ck-part-1.html\"\u003eSignal the ATT\u0026CK: Part 1\u003c/a\u003e - Building a real-time threat detection capability with Tanium that focuses on documented adversarial techniques.\u003c/li\u003e\n\u003cli\u003eSANS Summit Archives (\u003ca href=\"https://www.sans.org/cyber-security-summit/archives/dfir\"\u003eDFIR\u003c/a\u003e, \u003ca href=\"https://www.sans.org/cyber-security-summit/archives/cyber-defense\"\u003eCyber Defense\u003c/a\u003e) - Threat hunting, Blue Team and DFIR summit slides\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://svs.informatik.uni-hamburg.de/publications/2018/2018-05-31-Haas-QueryCon-Bro-Osquery.pdf\"\u003eBro-Osquery\u003c/a\u003e - Large-Scale Host and Network Monitoring Using Open-Source Software\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Karneades/malware-persistence\"\u003eMalware Persistence\u003c/a\u003e - Collection of various information focused on malware persistence: detection (techniques), response, pitfalls and the log collection (tools).\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://posts.specterops.io/threat-hunting-with-jupyter-notebooks-part-1-your-first-notebook-9a99a781fde7\"\u003eThreat Hunting with Jupyter Notebooks\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://dropbox.tech/security/how-dropbox-security-builds-better-tools-for-threat-detection-and-incident-response\"\u003eHow Dropbox Security builds tools for threat detection and incident response\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.elastic.co/blog/introducing-event-query-language\"\u003eIntroducing Event Query Language\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.varonis.com/blog/guide-no-hassle-eql-threat-hunting/\"\u003eThe No Hassle Guide to Event Query Language (EQL) for Threat Hunting\u003c/a\u003e (\u003ca href=\"docs/varonis.com-EQLforThreatHunting.pdf\"\u003ePDF\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://posts.specterops.io/introducing-the-funnel-of-fidelity-b1bb59b04036\"\u003eIntroducing the Funnel of Fidelity\u003c/a\u003e (\u003ca href=\"docs/specterops-IntroducingtheFunnelofFidelity.pdf\"\u003ePDF\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://posts.specterops.io/detection-spectrum-198a0bfb9302\"\u003eDetection Spectrum\u003c/a\u003e (\u003ca href=\"docs/specterops-DetectionSpectrum.pdf\"\u003ePDF\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://posts.specterops.io/capability-abstraction-fbeaeeb26384\"\u003eCapability Abstraction\u003c/a\u003e (\u003ca href=\"docs/specterops-CapabilityAbstraction.pdf\"\u003ePDF\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/InQuest/awesome-yara\"\u003eAwesome YARA\u003c/a\u003e - A curated list of awesome YARA rules, tools, and resources\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/mitre-attack/defining-attack-data-sources-part-i-4c39e581454f\"\u003eDefining ATT\u0026CK Data Sources\u003c/a\u003e - A two-part blog series that outlines a new methodology to extend ATT\u0026amp;CK’s current data sources.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.mbsecure.nl/blog/2019/5/dettact-mapping-your-blue-team-to-mitre-attack\"\u003eDETT\u0026CT: MAPPING YOUR BLUE TEAM TO MITRE ATT\u0026CK™\u003c/a\u003e - A blog that describes how to align MITRE ATT\u0026amp;CK-based detection content with data sources.\u003c/li\u003e\n\u003cli\u003eDetection as Code in Splunk \u003ca href=\"https://www.splunk.com/en_us/blog/security/ci-cd-detection-engineering-splunk-security-content-part-1.html\"\u003ePart 1, \u003c/a\u003e\u003ca href=\"https://www.splunk.com/en_us/blog/security/ci-cd-detection-engineering-splunk-s-attack-range-part-2.html\"\u003ePart 2, \u003c/a\u003e\u003ca href=\"https://www.splunk.com/en_us/blog/security/ci-cd-detection-engineering-failing-part-3.html\"\u003eand Part 3\u003c/a\u003e - A multipart series describing how detection as code can be successfully deployed in a Splunk environment.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/starting-up-security/lessons-learned-in-detection-engineering-304aec709856\"\u003eLessons Learned in Detection Engineering\u003c/a\u003e - A well experienced detection engineer describes in detail his observations, challenges, and recommendations for building an effective threat detection program.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://ateixei.medium.com/a-research-driven-process-applied-to-threat-detection-engineering-inputs-1b7e6fe0412b\"\u003eA Research-Driven process applied to Threat Detection Engineering Inputs\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://ohmymalware.com\"\u003eA video series focused on malware execution and investigations using Elastic Security\u003c/a\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"frameworks\"\u003eFrameworks\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://attack.mitre.org/wiki/Main_Page\"\u003eMITRE ATT\u0026CK\u003c/a\u003e - A curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/palantir/alerting-detection-strategy-framework\"\u003eAlerting and Detection Strategies Framework\u003c/a\u003e - A framework for developing alerting and detection strategies.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://detect-respond.blogspot.com.au/2015/10/a-simple-hunting-maturity-model.html\"\u003eA Simple Hunting Maturity Model\u003c/a\u003e - The Hunting Maturity Model describes five levels of organizational hunting capability, ranging from HMM0 (the least capability) to HMM4 (the most).\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://detect-respond.blogspot.com.au/2013/03/the-pyramid-of-pain.html\"\u003eThe Pyramic of Pain\u003c/a\u003e - The relationship between the types of indicators you might use to detect an adversary's activities and how much pain it will cause them when you are able to deny those indicators to them.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"docs/Framework-for-Threat-Hunting-Whitepaper.pdf\"\u003eA Framework for Cyber Threat Hunting\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://threathunter.guru/blog/the-paris-model/\"\u003eThe PARIS Model\u003c/a\u003e - A model for threat hunting.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.lockheedmartin.com/us/what-we-do/aerospace-defense/cyber/cyber-kill-chain.html\"\u003eCyber Kill Chain\u003c/a\u003e - It is part of the Intelligence Driven Defense® model for identification and prevention of cyber intrusions activity. The model identifies what the adversaries must complete in order to achieve their objective.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://ryanstillions.blogspot.com.au/2014/04/the-dml-model_21.html\"\u003eThe DML Model\u003c/a\u003e - The Detection Maturity Level (DML) model is a capability maturity model for referencing ones maturity in detecting cyber attacks.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.nist.gov/cyberframework\"\u003eNIST Cybersecurity Framework\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hunters-forge/OSSEM\"\u003eOSSEM\u003c/a\u003e (Open Source Security Events Metadata) - A community-led project that focuses on the documentation and standardization of security event logs from diverse data sources and operating systems.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ocsf/ocsf-schema\"\u003eOpen Cybersecurity Schema Framework (OCSF)\u003c/a\u003e -  A framework for creating schemas and it also delivers a cybersecurity event schema built with the framework (\u003ca href=\"https://schema.ocsf.io/\"\u003eschema browser\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://engage.mitre.org/\"\u003eMITRE Engage\u003c/a\u003e - A framework for planning and discussing adversary engagement operations that empowers you to engage your adversaries and achieve your cybersecurity goals.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.betaalvereniging.nl/wp-content/uploads/FI-ISAC-use-case-framework-verkorte-versie.pdf\"\u003eMaGMa Use Case Defintion Model\u003c/a\u003e - A business-centric approach for planning and defining threat detection use cases.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"windows\"\u003eWindows\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"docs/Threat%20Hunting%20via%20Windows%20Event%20Logs%20Secwest%202019.pdf\"\u003eThreat Hunting via Windows Event Logs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.malwarearchaeology.com/cheat-sheets/\"\u003eWindows Logging Cheat Sheets\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://adsecurity.org/wp-content/uploads/2017/04/2017-BSidesCharm-DetectingtheElusive-ActiveDirectoryThreatHunting-Final.pdf\"\u003eActive Directory Threat Hunting\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/beahunt3r/Windows-Hunting\"\u003eWindows Hunting\u003c/a\u003e - A collection of Windows hunting queries\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blogs.jpcert.or.jp/en/2016/01/windows-commands-abused-by-attackers.html\"\u003eWindows Commands Abused by Attackers\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blogs.jpcert.or.jp/en/2017/12/research-report-released-detecting-lateral-movement-through-tracking-event-logs-version-2.html\"\u003eJPCERT - Detecting Lateral Movement through Tracking Event Logs\u003c/a\u003e\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://jpcertcc.github.io/ToolAnalysisResultSheet/\"\u003eTool Analysis Result Sheet\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"sysmon\"\u003eSysmon\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/@haggis_m/splunking-the-endpoint-threat-hunting-with-sysmon-9dd956e3e1bd\"\u003eSplunking the Endpoint: Threat Hunting with Sysmon\u003c/a\u003e\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/@haggis_m/hunting-with-sysmon-38de012e62e6\"\u003eHunting with Sysmon\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://www.syspanda.com/index.php/2017/10/10/threat-hunting-sysmon-word-document-macro/\"\u003eThreat Hunting with Sysmon: Word Document with Macro\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eChronicles of a Threat Hunter: Hunting for In-Memory Mimikatz with Sysmon and ELK\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://cyberwardog.blogspot.com.au/2017/03/chronicles-of-threat-hunter-hunting-for.html\"\u003ePart I (Event ID 7)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://cyberwardog.blogspot.com.au/2017/03/chronicles-of-threat-hunter-hunting-for_22.html\"\u003ePart II (Event ID 10)\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003eAdvanced Incident Detection and Threat Hunting using Sysmon (and Splunk) (\u003ca href=\"https://www.botconf.eu/wp-content/uploads/2016/11/PR12-Sysmon-UELTSCHI.pdf\"\u003ebotconf 2016 Slides\u003c/a\u003e, \u003ca href=\"https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf\"\u003eFIRST 2017 Slides\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.peerlyst.com/posts/the-sysmon-and-threat-hunting-mimikatz-wiki-for-the-blue-team-guurhart\"\u003eThe Sysmon and Threat Hunting Mimikatz wiki for the blue team\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.crypsisgroup.com/wp-content/uploads/2017/07/CG_WhitePaper_Splunkmon_1216-1.pdf\"\u003eSplunkmon — Taking Sysmon to the Next Level\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.varonis.com/blog/sysmon-threat-detection-guide/\"\u003eSysmon Threat Detection Guide\u003c/a\u003e (\u003ca href=\"docs/varonis.com-SysmonThreatAnalysisGuide.pdf\"\u003ePDF\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4 id=\"powershell\"\u003ePowerShell\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eRevoke-Obfuscation: PowerShell Obfuscation Detection Using Science (\u003ca href=\"https://www.blackhat.com/docs/us-17/thursday/us-17-Bohannon-Revoke-Obfuscation-PowerShell-Obfuscation-Detection-And%20Evasion-Using-Science-wp.pdf\"\u003ePaper\u003c/a\u003e, \u003ca href=\"https://www.blackhat.com/docs/us-17/thursday/us-17-Bohannon-Revoke-Obfuscation-PowerShell-Obfuscation-Detection-And%20Evasion-Using-Science.pdf\"\u003eSlides\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://conf.splunk.com/files/2016/slides/hunting-the-known-unknowns-the-powershell-edition.pdf\"\u003eHunting the Known Unknowns (With PowerShell)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.splunk.com/blog/2017/07/06/hellsbells-lets-hunt-powershells.html\"\u003eHellsBells, Let's Hunt PowerShells!\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/@jshlbrd/hunting-for-powershell-using-heatmaps-69b70151fa5d\"\u003eHunting for PowerShell Using Heatmaps\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"macos\"\u003eMacOS\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"docs/SentinalOne_macOS_Threat_Hunting_and_Incident_Response_A_Complete_Guide_17032020-1.pdf\"\u003eA Guide to macOS Threat Hunting and Incident Response\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"osquery\"\u003eOsquery\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/@palantir/osquery-across-the-enterprise-3c3c9d13ec55\"\u003eosquery Across the Enterprise\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/@clong/osquery-for-security-b66fffdf2daf\"\u003eosquery for Security — Part 1\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/@clong/osquery-for-security-part-2-2e03de4d3721\"\u003eosquery for Security — Part 2\u003c/a\u003e - Advanced osquery functionality, File integrity monitoring, process auditing, and more.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blog.trailofbits.com/2017/10/10/tracking-a-stolen-code-signing-certificate-with-osquery/\"\u003eTracking a stolen code-signing certificate with osquery\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blog.kolide.com/monitoring-macos-hosts-with-osquery-ba5dcc83122d\"\u003eMonitoring macOS hosts with osquery\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blog.kolide.com/\"\u003eKolide's Blog\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/trailofbits/presentations/tree/master/Osquery%20Extensions\"\u003eThe osquery Extensions Skunkworks Project\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"dns\"\u003eDNS\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.sans.org/reading-room/whitepapers/dns/detecting-dns-tunneling-34152\"\u003eDetecting DNS Tunneling\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.splunk.com/pdfs/events/govsummit/hunting_the_known_unknowns_with_DNS.pdf\"\u003eHunting the Known Unknowns (with DNS)\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html\"\u003eDetecting dynamic DNS domains in Splunk\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.splunk.com/blog/2015/10/01/random-words-on-entropy-and-dns.html\"\u003eRandom Words on Entropy and DNS\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://isc.sans.edu/diary/Tracking+Newly+Registered+Domains/23127\"\u003eTracking Newly Registered Domains\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://isc.sans.edu/forums/diary/Suspicious+Domains+Tracking+Dashboard/23046/\"\u003eSuspicious Domains Tracking Dashboard\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://isc.sans.edu/forums/diary/Proactive+Malicious+Domain+Search/23065/\"\u003eProactive Malicious Domain Search\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.first.org/resources/papers/conf2017/DNS-is-NOT-Boring-Using-DNS-to-Expose-and-Thwart-Attacks.pdf\"\u003eDNS is NOT Boring\u003c/a\u003e - Using DNS to Expose and Thwart Attacks\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://prezi.com/vejpnxkm85ih/actionable-detects-dns-keynote/\"\u003eActionable Detects\u003c/a\u003e - Blue Team Tactics\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"fingerprinting\"\u003eFingerprinting\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://engineering.salesforce.com/open-sourcing-ja3-92c9e53c3c41\"\u003eJA3: SSL/TLS Client Fingerprinting for Malware Detection\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://engineering.salesforce.com/tls-fingerprinting-with-ja3-and-ja3s-247362855967\"\u003eTLS Fingerprinting with JA3 and JA3S\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://engineering.salesforce.com/open-sourcing-hassh-abed3ae5044c\"\u003eHASSH - a profiling method for SSH Clients and Servers\u003c/a\u003e\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/benjeems/Presentations/blob/master/BSides%202019%20%20-%20HASSH%20-%20a%20Profiling%20Method%20for%20SSH%20Clients%20and%20Servers.pdf\"\u003eHASSH \u003ca href=\"https://github.com/BSides\"\u003e@BSides\u003c/a\u003e Canberra 2019 - Slides\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://engineering.salesforce.com/finding-evil-on-the-network-using-ja3-s-and-hassh-11431a8606e4\"\u003eFinding Evil on the Network Using JA3/S and HASSH\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/@0x4d31/rdp-client-fingerprinting-9e7ac219f7f4\"\u003eRDP Fingerprinting - Profiling RDP Clients with JA3 and RDFP\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.ntop.org/ndpi/effective-tls-fingerprinting-beyond-ja3/\"\u003eEffective TLS Fingerprinting Beyond JA3\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blogs.cisco.com/security/tls-fingerprinting-in-the-real-world\"\u003eTLS Fingerprinting in the Real World\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.ssllabs.com/projects/client-fingerprinting/\"\u003eHTTP Client Fingerprinting Using SSL Handshake Analysis\u003c/a\u003e (source code: \u003ca href=\"https://github.com/ssllabs/sslhaf\"\u003emod_sslhaf\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blog.squarelemon.com/tls-fingerprinting/\"\u003eTLS fingerprinting - Smarter Defending \u0026 Stealthier Attacking\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://ja3er.com\"\u003eJA3er\u003c/a\u003e - a DB of JA3 fingerprints\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.net-square.com/httprint_paper.html\"\u003eAn Introduction to HTTP fingerprinting\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://tlsfingerprint.io/\"\u003eTLS Fingerprints\u003c/a\u003e collected from the University of Colorado Boulder campus network\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://tlsfingerprint.io/static/frolov2019.pdf\"\u003eThe use of TLS in Censorship Circumvention\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://dl.acm.org/doi/pdf/10.1145/3355369.3355601\"\u003eTLS Beyond the Browser: Combining End Host and Network Data to Understand Application Behavior\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://link.springer.com/article/10.1186/s13635-016-0030-7\"\u003eHTTPS traffic analysis and client identification using passive SSL/TLS fingerprinting\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://drakkar.imag.fr/IMG/pdf/1569811033.pdf\"\u003eMarkov Chain Fingerprinting to Classify Encrypted Traffic\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.conand.me/publications/bortolameotti-headprint-2020.pdf\"\u003eHeadPrint: Detecting Anomalous Communications through Header-based Application Fingerprinting\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"data-science\"\u003eData Science\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SuperCowPowers/data_hacking\"\u003edata_hacking\u003c/a\u003e - Examples of using IPython, Pandas, and Scikit Learn to get the most out of your security data.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.mandiant.com/resources/blog/build-machine-learning-models-for-the-soc\"\u003eReverse engineering the analyst: building machine learning models for the SOC\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/microsoft/msticpy\"\u003emsticpy\u003c/a\u003e - A library for InfoSec investigation and hunting in Jupyter Notebooks.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"research-papers\"\u003eResearch Papers\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.lockheedmartin.com/content/dam/lockheed/data/corporate/documents/LM-White-Paper-Intel-Driven-Defense.pdf\"\u003eIntelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://www.activeresponse.org/wp-content/uploads/2013/07/diamond.pdf\"\u003eThe Diamond Model of Intrusion Analysis\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.cs.ucsb.edu/~chris/research/doc/ndss11_exposure.pdf\"\u003eEXPOSURE: Finding Malicious Domains Using Passive DNS Analysis\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eA Comprehensive Approach to Intrusion Detection Alert Correlation (\u003ca href=\"https://www.cs.ucsb.edu/~vigna/publications/2004_valeur_vigna_kruegel_kemmerer_TDSC_Correlation.pdf\"\u003ePaper\u003c/a\u003e, \u003ca href=\"http://citeseerx.ist.psu.edu/viewdoc/download?doi=10.1.1.115.8310\u0026rep=rep1\u0026type=pdf\"\u003eDissertation\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://www.few.vu.nl/~herbertb/papers/feederbot_ec2nd11.pdf\"\u003eOn Botnets that use DNS for Command and Control\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://dl.acm.org/citation.cfm?id=2991111\"\u003eIntelligent, Automated Red Team Emulation\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://dl.acm.org/doi/pdf/10.1145/3097983.3098163\"\u003eMachine Learning for Encrypted Malware Traffic Classification\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"blogs\"\u003eBlogs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://detect-respond.blogspot.com\"\u003eDavid Bianco's Blog\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"http://findingbad.blogspot.com\"\u003eDFIR and Threat Hunting Blog\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/@Cyb3rWard0g\"\u003eCyberWardog's Blog\u003c/a\u003e (\u003ca href=\"https://cyberwardog.blogspot.com\"\u003eold\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://chrissanders.org\"\u003eChris Sanders' Blog\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blog.kolide.com/\"\u003eKolide Blog\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://medium.com/anton-on-security\"\u003eAnton Chuvakin\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://ateixei.medium.com\"\u003eAlexandre Teixeira\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3 id=\"related-awesome-lists\"\u003eRelated Awesome Lists\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jatrost/awesome-kubernetes-threat-detection\"\u003eAwesome Kubernetes Threat Detection\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/meirwah/awesome-incident-response\"\u003eAwesome Incident Response\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/cugu/awesome-forensics\"\u003eAwesome Forensics\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/paralax/awesome-honeypots\"\u003eAwesome Honeypots\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/rshipp/awesome-malware-analysis\"\u003eAwesome Malware Analysis\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/InQuest/awesome-yara\"\u003eAwesome YARA\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sbilly/awesome-security\"\u003eAwesome Security\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/4ndersonLin/awesome-cloud-security\"\u003eAwesome Cloud Security\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"podcasts\"\u003ePodcasts\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eGoogle \u003ca href=\"https://cloud.withgoogle.com/cloudsecurity/podcast/\"\u003eCloud Security Podcast\u003c/a\u003e by Anton Chuvakin and Timothy Peacock.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.dcppodcast.com/all-episodes\"\u003eDetection: Challenging Paradigms\u003c/a\u003e by SpecterOps\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://darknetdiaries.com\"\u003eDarknet Diaries\u003c/a\u003e by Andy Greenberg - True stories from the dark side of the Internet.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://risky.biz\"\u003eRisky Business\u003c/a\u003e by Patrick Gray\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"newsletters\"\u003eNewsletters\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.detectionengineering.net\"\u003eDetection Engineering Weekly\u003c/a\u003e by Zack 'techy' Allen\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://thisweekin4n6.com\"\u003eThis Week in 4n6\u003c/a\u003e - A weekly roundup of digital forensics and incident response news.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"videos\"\u003eVideos\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/playlist?list=PLfouvuAjspTr95R60Kt7ZcoerR6tYoCLA\"\u003eSANS Threat Hunting and IR Summit 2017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/playlist?list=PLfouvuAjspTokaa-LdUHqszL-KACkCsKT\"\u003eSANS Threat Hunting and IR Summit 2016\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=vv_VXntQTpE\"\u003eBotConf 2016 - Advanced Incident Detection and Threat Hunting using Sysmon and Splunk\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=9Uo7V9OUaUw\"\u003eBSidesCharm 2017 - Detecting the Elusive: Active Directory Threat Hunting\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=c-c-IQ5pFXw\"\u003eBSidesAugusta 2017 - Machine Learning Fueled Cyber Threat Hunting\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=7q7GGg-Ws9s\"\u003eToppling the Stack: Outlier Detection for Threat Hunters\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=bDdsGBCUa8I\"\u003eBSidesPhilly 2017 - Threat Hunting: Defining the Process While Circumventing Corporate Obstacles\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=x97ejtv56xw\"\u003eBlack Hat 2017 - Revoke-Obfuscation: PowerShell Obfuscation Detection (And Evasion) Using Science\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=LUtluTaEAUU\"\u003eDefCon 25 - MS Just Gave the Blue Team Tactical Nukes\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=19H7j_sZcKc\"\u003eBSides London 2017 - Hunt or be Hunted\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=_QVhMPGtIeU\"\u003eSecurityOnion 2017 - Pivoting Effectively to Catch More Bad Guys\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=mKxGulV2Z74\"\u003eSkyDogCon 2016 - Hunting: Defense Against The Dark Arts\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=1mfVPLPxKTc\"\u003eBSidesAugusta 2017 - Don't Google 'PowerShell Hunting'\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=8qM-DnmHNv8\"\u003eBSidesAugusta 2017 - Hunting Adversaries w Investigation Playbooks \u0026 OpenCNA\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=98MrgfTFeMo\"\u003eVisual Hunting with Linked Data\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=zlAWbdSlhaQ\"\u003eRVAs3c - Pyramid of Pain: Intel-Driven Detection/Response to Increase Adversary's Cost\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=2MrrOxsJk_M\"\u003eBSidesLV 2016 - Hunting on the Endpoint w/ Powershell\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=MUUseTJp3jM\"\u003eDerbycon 2015 - Intrusion Hunting for the Masses A Practical Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=2FvP7nwb2UE\u0026feature=youtu.be\"\u003eBSides DC 2016 - Practical Cyborgism: Getting Start with Machine Learning for Incident Detection\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=7JIftAw8wQY\"\u003eSANS Webcast 2018 - What Event Logs? Part 1: Attacker Tricks to Remove Event Logs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=oprPu7UIEuk\"\u003eProfiling And Detecting All Things SSL With JA3\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=kG-kenOypLk\"\u003eACoD 2019 - HASSH SSH Client/Server Profiling\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/playlist?list=PLlSdCcsTOu5STvaoPlr-PJE-zbYmlAGrX\"\u003eQueryCon 2018\u003c/a\u003e - An annual conference for the osquery open-source community (\u003ca href=\"https://querycon.io\"\u003equerycon.io\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=EpK7MkWCh1I\"\u003eVisual Hunting with Linked Data Graphs\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=A6hBoeSNJJw\"\u003eSecurityOnion Con 2018 - Introduction to Data Analysis\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=E2rbyoCFNY4\"\u003eInsider Threats Detection at Airbus – AI up Against Data Leakage and Industrial Espionage\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.youtube.com/watch?v=bOOVxGnbKxI\"\u003eCyber Security Investigations with Jupyter Notebooks\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"trainings\"\u003eTrainings\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://www.networkdefense.co/courses/\"\u003eApplied Network Defense\u003c/a\u003e courses by Chris Sanders\u003c/li\u003e\n\u003cli\u003eInvestigation theory, Practical threat hunting, Detection engineering with Sigma, etc.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://securityblue.team/\"\u003eSecurity Blue Team\u003c/a\u003e (BTL1 and BTL2 certificates)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://letsdefend.io\"\u003eLetsDefend\u003c/a\u003e - Hands-On SOC Analyst Training\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://tryhackme.com\"\u003eTryHackMe\u003c/a\u003e - Hands-on cyber security training through real-world scenarios.\u003c/li\u003e\n\u003cli\u003e13Cubed, \u003ca href=\"https://training.13cubed.com/investigating-windows-endpoints\"\u003eInvestigating Windows Endpoints\u003c/a\u003e by Richard Davis\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://academy.hackthebox.com/\"\u003eHackTheBox\u003c/a\u003e - While not directly related to threat detection, the website features training modules on general security and offensive topics that can be beneficial for junior SOC analysts.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"labs\"\u003eLabs\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/clong/DetectionLab/\"\u003eDetectionLab\u003c/a\u003e - Vagrant \u0026amp; Packer scripts to build a lab environment complete with security tooling and logging best practices.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bots.splunk.com/\"\u003eSplunk Boss of the SOC\u003c/a\u003e - Hands-on workshops and challenges to practice threat hunting using the BOTS and other datasets.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Cyb3rWard0g/HELK\"\u003eHELK\u003c/a\u003e - A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/op7ic/BlueTeam.Lab\"\u003eBlueTeam Lab\u003c/a\u003e - A detection lab created with Terraform and Ansible in Azure.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/splunk/attack_range\"\u003eattack_range\u003c/a\u003e - A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"twitter\"\u003eTwitter\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://twitter.com/0x4d31/lists/awesome-detection\"\u003e\"Awesome Detection\" Twitter List\u003c/a\u003e - Twitter accounts that tweet about threat detection, hunting and DFIR.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"threat-simulation-tools\"\u003eThreat Simulation Tools\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mitre/caldera\"\u003eMITRE CALDERA\u003c/a\u003e - An automated adversary emulation system that performs post-compromise adversarial behavior within Windows Enterprise networks.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/NextronSystems/APTSimulator\"\u003eAPTSimulator\u003c/a\u003e - A Windows Batch script that uses a set of tools and output files to make a system look as if it was compromised.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/redcanaryco/atomic-red-team\"\u003eAtomic Red Team\u003c/a\u003e - Small and highly portable detection tests mapped to the Mitre ATT\u0026amp;CK Framework.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/alphasoc/flightsim\"\u003eNetwork Flight Simulator\u003c/a\u003e - flightsim is a lightweight utility used to generate malicious network traffic and help security teams to evaluate security controls and network visibility.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/uber-common/metta\"\u003eMetta\u003c/a\u003e - A security preparedness tool to do adversarial simulation.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/endgameinc/RTA\"\u003eRed Team Automation (RTA)\u003c/a\u003e - RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT\u0026amp;CK.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mdsecactivebreach/SharpShooter\"\u003eSharpShooter\u003c/a\u003e - Payload Generation Framework.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mdsecactivebreach/CACTUSTORCH\"\u003eCACTUSTORCH\u003c/a\u003e - Payload Generation for Adversary Simulations.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TryCatchHCF/DumpsterFire\"\u003eDumpsterFire\u003c/a\u003e - A modular, menu-driven, cross-platform tool for building repeatable, time-delayed, distributed security events.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/EmpireProject/Empire\"\u003eEmpire\u003c/a\u003e(\u003ca href=\"http://www.powershellempire.com\"\u003ewebsite\u003c/a\u003e) - A PowerShell and Python post-exploitation agent.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/PowerShellMafia/PowerSploit/\"\u003ePowerSploit\u003c/a\u003e - A PowerShell Post-Exploitation Framework.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/redhuntlabs/RedHunt-OS\"\u003eRedHunt-OS\u003c/a\u003e - A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/guardicore/monkey\"\u003eInfection Monkey\u003c/a\u003e - An open source Breach and Attack Simulation (BAS) tool that assesses the resiliency of private and public cloud environments to post-breach attacks and lateral movement.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/splunk/attack_range\"\u003eSplunk Attack Range\u003c/a\u003e - A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"threat-simulation-resources\"\u003eThreat Simulation Resources\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://attack.mitre.org/wiki/Adversary_Emulation_Plans\"\u003eMITRE's Adversary Emulation Plans\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yeyintminthuhtut/Awesome-Red-Teaming\"\u003eAwesome Red Teaming\u003c/a\u003e - A list of awesome red teaming resources\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bluscreenofjeff/Red-Team-Infrastructure-Wiki\"\u003eRed-Team Infrastructure Wiki\u003c/a\u003e - Wiki to collect Red Team infrastructure hardening resources.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.mdsec.co.uk/2018/03/payload-generation-using-sharpshooter/\"\u003ePayload Generation using SharpShooter\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://posts.specterops.io/\"\u003eSpecterOps Blog\u003c/a\u003e\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://posts.specterops.io/tagged/threat-hunting\"\u003eThreat Hunting\u003c/a\u003e\u003c/li\u003e\u003c/ul\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://blog.cobaltstrike.com/2015/09/30/advanced-threat-tactics-course-and-notes/\"\u003eAdvanced Threat Tactics\u003c/a\u003e - A free course on red team operations and adversary simulations.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.pwc.co.uk/issues/cyber-security-data-privacy/research/signal-att-and-ck-part-1.html\"\u003eSignal the ATT\u0026CK: Part 1\u003c/a\u003e - Modelling APT32 in CALDERA\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/infosecn1nja/Red-Teaming-Toolkit\"\u003eRed Teaming/Adversary Simulation Toolkit\u003c/a\u003e - A collection of open source and commercial tools that aid in red team operations.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://www.thec2matrix.com/matrix\"\u003eC2 Matrix\u003c/a\u003e (\u003ca href=\"https://docs.google.com/spreadsheets/d/1b4mUxa6cDQuTV2BPC6aA-GR4zGZi0ooPYtBe4IgPsSc\"\u003eGoogle Sheets\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/center-for-threat-informed-defense/adversary_emulation_library\"\u003eadversary\u003cem\u003eemulation\u003c/em\u003elibrary\u003c/a\u003e - An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2 id=\"contribute\"\u003eContribute\u003c/h2\u003e\n\u003cp\u003eContributions welcome! Read the \u003ca href=\"CONTRIBUTING.md\"\u003econtribution guidelines\u003c/a\u003e first.\u003c/p\u003e\n\u003ch2 id=\"license\"\u003eLicense\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"http://creativecommons.org/publicdomain/zero/1.0\"\u003e\u003cimg src=\"http://mirrors.creativecommons.org/presskit/buttons/88x31/svg/cc-zero.svg\" alt=\"CC0\" /\u003e\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eTo the extent possible under law, Adel \u0026#34;0x4D31\u0026#34; Karimi has waived all copyright and\u003cbr /\u003e\nrelated or neighboring rights to this work.\u003c/p\u003e\n\n          \u003c/div\u003e\n          \u003cstyle type='text/css'\u003ebody {\n    font: 400 16px/1.5 \"Helvetica Neue\", Helvetica, Arial, sans-serif;\n    color: #111;\n    background-color: #fbfbfb;\n    -webkit-text-size-adjust: 100%;\n    -webkit-font-feature-settings: \"kern\" 1;\n    -moz-font-feature-settings: \"kern\" 1;\n    -o-font-feature-settings: \"kern\" 1;\n    font-feature-settings: \"kern\" 1;\n    font-kerning: normal;\n    padding: 30px;\n}\n\n@media only screen and (max-width: 600px) {\n    body {\n        padding: 5px;\n    }\n    body\u003e#content {\n        padding: 0px 20px 20px 20px !important;\n    }\n}\n\nbody\u003e#content {\n    margin: 0px;\n    max-width: 900px;\n    border: 1px solid #e1e4e8;\n    padding: 10px 40px;\n    padding-bottom: 20px;\n    border-radius: 2px;\n    margin-left: auto;\n    margin-right: auto;\n}\n\nsummary {\n    cursor: pointer;\n    text-decoration: underline;\n}\n\nhr {\n    color: #bbb;\n    background-color: #bbb;\n    height: 1px;\n    flex: 0 1 auto;\n    margin: 1em 0;\n    padding: 0;\n    border: none;\n}\n\n.hljs-operator {\n    color: #868686;\n    /* There is a bug where the syntax highlighter would pick no color for e.g. `\u0026\u0026` symbols in the code samples. Let's overwrite this */\n}\n\n\n/**\n * Links\n */\n\na {\n    color: #0366d6;\n    text-decoration: none;\n}\n\na:visited {\n    color: #0366d6;\n}\n\na:hover {\n    color: #0366d6;\n    text-decoration: underline;\n}\n\npre {\n    background-color: #f6f8fa;\n    border-radius: 3px;\n    font-size: 85%;\n    line-height: 1.45;\n    overflow: auto;\n    padding: 16px;\n}\n\n\n/**\n  * Code blocks\n  */\n\ncode {\n    background-color: rgba(27, 31, 35, .05);\n    border-radius: 3px;\n    font-size: 85%;\n    margin: 0;\n    word-wrap: break-word;\n    padding: .2em .4em;\n    font-family: SFMono-Regular, Consolas, Liberation Mono, Menlo, Courier, monospace;\n}\n\npre\u003ecode {\n    background-color: transparent;\n    border: 0;\n    display: inline;\n    line-height: inherit;\n    margin: 0;\n    overflow: visible;\n    padding: 0;\n    word-wrap: normal;\n    font-size: 100%;\n}\n\n\n/**\n * Blockquotes\n */\n\nblockquote {\n    margin-left: 30px;\n    margin-top: 0px;\n    margin-bottom: 16px;\n    border-left-width: 3px;\n    padding: 0 1em;\n    color: #828282;\n    border-left: 4px solid #e8e8e8;\n    padding-left: 15px;\n    font-size: 18px;\n    letter-spacing: -1px;\n    font-style: italic;\n}\n\nblockquote * {\n    font-style: normal !important;\n    letter-spacing: 0;\n    color: #6a737d !important;\n}\n\n\n/**\n * Tables\n */\n\ntable {\n    border-spacing: 2px;\n    display: block;\n    font-size: 14px;\n    overflow: auto;\n    width: 100%;\n    margin-bottom: 16px;\n    border-spacing: 0;\n    border-collapse: collapse;\n}\n\ntd {\n    padding: 6px 13px;\n    border: 1px solid #dfe2e5;\n}\n\nth {\n    font-weight: 600;\n    padding: 6px 13px;\n    border: 1px solid #dfe2e5;\n}\n\ntr {\n    background-color: #fff;\n    border-top: 1px solid #c6cbd1;\n}\n\ntable tr:nth-child(2n) {\n    background-color: #f6f8fa;\n}\n\n\n/**\n * Others\n */\n\nimg {\n    max-width: 100%;\n}\n\np {\n    line-height: 24px;\n    font-weight: 400;\n    font-size: 16px;\n    color: #24292e;\n}\n\nul {\n    margin-top: 0;\n}\n\nli {\n    color: #24292e;\n    font-size: 16px;\n    font-weight: 400;\n    line-height: 1.5;\n}\n\nli+li {\n    margin-top: 0.25em;\n}\n\n* {\n    font-family: -apple-system, BlinkMacSystemFont, \"Segoe UI\", Helvetica, Arial, sans-serif, \"Apple Color Emoji\", \"Segoe UI Emoji\", \"Segoe UI Symbol\";\n    color: #24292e;\n}\n\na:visited {\n    color: #0366d6;\n}\n\nh1,\nh2,\nh3 {\n    border-bottom: 1px solid #eaecef;\n    color: #111;\n    /* Darker */\n}\n\ncode\u003e* {\n    font-family: Consolas, \"Liberation Mono\", Menlo, Courier, monospace !important;\n}\u003c/style\u003e\n          \u003cstyle type='text/css'\u003epre code.hljs{display:block;overflow-x:auto;padding:1em}code.hljs{padding:3px 5px}.hljs{color:#abb2bf;background:#282c34}.hljs-comment,.hljs-quote{color:#5c6370;font-style:italic}.hljs-doctag,.hljs-formula,.hljs-keyword{color:#c678dd}.hljs-deletion,.hljs-name,.hljs-section,.hljs-selector-tag,.hljs-subst{color:#e06c75}.hljs-literal{color:#56b6c2}.hljs-addition,.hljs-attribute,.hljs-meta .hljs-string,.hljs-regexp,.hljs-string{color:#98c379}.hljs-attr,.hljs-number,.hljs-selector-attr,.hljs-selector-class,.hljs-selector-pseudo,.hljs-template-variable,.hljs-type,.hljs-variable{color:#d19a66}.hljs-bullet,.hljs-link,.hljs-meta,.hljs-selector-id,.hljs-symbol,.hljs-title{color:#61aeee}.hljs-built_in,.hljs-class .hljs-title,.hljs-title.class_{color:#e6c07b}.hljs-emphasis{font-style:italic}.hljs-strong{font-weight:700}.hljs-link{text-decoration:underline}\u003c/style\u003e\n        \u003c/body\u003e\n      \u003c/html\u003e\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2F0x4D31%2Fawesome-threat-detection","html_url":"https://awesome.ecosyste.ms/projects/github.com%2F0x4D31%2Fawesome-threat-detection","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2F0x4D31%2Fawesome-threat-detection/lists"}