{"id":13454125,"url":"https://github.com/A3sal0n/CyberThreatHunting","last_synced_at":"2025-03-24T05:33:22.590Z","repository":{"id":37951266,"uuid":"83138303","full_name":"A3sal0n/CyberThreatHunting","owner":"A3sal0n","description":"A collection of resources for Threat Hunters","archived":false,"fork":false,"pushed_at":"2024-10-15T18:48:37.000Z","size":43904,"stargazers_count":855,"open_issues_count":1,"forks_count":169,"subscribers_count":63,"default_branch":"master","last_synced_at":"2024-11-18T10:36:08.005Z","etag":null,"topics":["cybersecurity","dfir","incident-response","threat-hunting","threat-intelligence"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/A3sal0n.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":"CODE_OF_CONDUCT.md","threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2017-02-25T14:47:59.000Z","updated_at":"2024-11-12T08:29:15.000Z","dependencies_parsed_at":"2023-01-27T22:45:47.700Z","dependency_job_id":"8385c6af-a28a-4de2-98f4-5aae1d8dcf2d","html_url":"https://github.com/A3sal0n/CyberThreatHunting","commit_stats":{"total_commits":50,"total_committers":7,"mean_commits":7.142857142857143,"dds":0.26,"last_synced_commit":"4fe7bfefaca2c6b5120bc34047951faf827a71b1"},"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/A3sal0n%2FCyberThreatHunting","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/A3sal0n%2FCyberThreatHunting/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/A3sal0n%2FCyberThreatHunting/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/A3sal0n%2FCyberThreatHunting/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/A3sal0n","download_url":"https://codeload.github.com/A3sal0n/CyberThreatHunting/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":245217337,"owners_count":20579290,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cybersecurity","dfir","incident-response","threat-hunting","threat-intelligence"],"created_at":"2024-07-31T08:00:51.086Z","updated_at":"2025-03-24T05:33:17.581Z","avatar_url":"https://github.com/A3sal0n.png","language":"Python","funding_links":[],"categories":["Threat Detection and Hunting","Python (1887)","Python"],"sub_categories":["Resources"],"readme":"# Cyber Threat Hunting\nA collection of tools and other resources for threat hunters.\n\n## Sections\n- [Hunting Tools](#hunting-tools) - A collection of our open source tools for hunting\n- [Resources](#resources) - Useful resources to get started in Threat Hunting\n- [Hunting with AI](#hunting-with-ai) - Leverage the power of ChatGPT prompts for Threat Hunting\n- [Must Read](#must-read) - Articles and blog posts covering different aspects of Threat Hunting\n- [Custom Scripts](tools/README.md) - Our own tools and scripts to support different types of hunts\n\n### Hunting Tools\n- [Velociraptor](https://docs.velociraptor.app/)\n- [Facebook's osquery](https://osquery.io/)\n- [Google's GRR](https://github.com/google/grr)\n- [Logging, searching and visualization with ELK](https://www.elastic.co/products/elasticsearch)\n- [Back to Basics: Enhance Windows Security with Sysmon and Graylog](https://www.graylog.org/blog/83-back-to-basics-enhance-windows-security-with-sysmon-and-graylog)\n- [Building a Sysmon Dashboard with an ELK Stack](https://cyberwardog.blogspot.cz/2017/03/building-sysmon-dashboard-with-elk-stack.html)\n- [Advanced Sysmon configuration, Installer \u0026 Auto Updater with high-quality event tracing](https://github.com/ion-storm/sysmon-config)\n- [Advanced Threat detection Configurations for Graylog](https://github.com/ion-storm/Graylog_Sysmon)\n- [Elk + Osquery + Kolide Fleet = Love](https://jordanpotti.com/2018/02/16/elk-osquery-kolide-fleet-love/) - Hunting with ELK, Osquery and Kolide Fleet\n- [CyLR — Live Response Collection tool](https://github.com/orlikoski/CyLR)\n- [Unix-like Artifacts Collector](https://github.com/tclahr/uac)\n- [Kroll Artifact Parser And Extractor (KAPE)](https://www.kroll.com/en/services/cyber-risk/incident-response-litigation-support/kroll-artifact-parser-extractor-kape)\n- [Chainsaw - Rapidly Search and Hunt through Windows Forensic Artefacts](https://github.com/WithSecureLabs/chainsaw)\n- [evtx-hunter - Python tool that generates a web report of interesting activity observed in EVTX files](https://github.com/NVISOsecurity/evtx-hunter)\n\n### Resources\n- [MITRE ATT\u0026CK](https://attack.mitre.org/wiki/Main_Page) - A curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target.\n- [MITRE CAR](https://car.mitre.org/wiki/Main_Page) - A knowledge base of analytics developed by MITRE based on the Adversary Tactics, Techniques, and Common Knowledge (ATT\u0026CK™) threat model.\n- [Threat Hunting with Bro IDS](https://www.jamesbower.com/threat-hunting-with-bro-ids/?utm_campaign=crowdfire\u0026utm_content=crowdfire\u0026utm_medium=social\u0026utm_source=social#14225595-tw%231487983917678)\n- [Automating APT Scanning with Loki Scanner and Splunk](http://www.redblue.team/2017/04/automating-apt-scanning-with-loki.html?m=1)\n- [The ThreatHunting Project](https://github.com/ThreatHuntingProject/ThreatHunting) - A great collection of hunts by @DavidJBianco\n- [Threat Hunting Techniques - AV, Proxy, DNS and HTTP Logs](http://www.brainfold.net/2016/08/threat-hunting-techniques-av-proxy-dns.html)\n- [Cyber Threat hunting with Sqrrl (From Beaconing to Lateral Movement)](https://cyber-ir.com/2017/04/19/cyber-threat-hunting-with-sqrrl-from-beaconing-to-lateral-movement/amp/)\n- [The ThreatHunter-Playbook](https://github.com/VVard0g/ThreatHunter-Playbook) - Hunting by leveraging Sysmon and Windows Events logs\n- [Detecting Lateral Movement through Tracking Event Logs](https://www.jpcert.or.jp/english/pub/sr/20170612ac-ir_research_en.pdf)\n- [How to build a Threat Hunting platform using ELK Stack](https://www.peerlyst.com/posts/how-to-build-a-threat-hunting-platform-using-elk-stack-chiheb-chebbi?utm_source=LinkedIn\u0026utm_medium=Application_Share\u0026utm_content=peerlyst_post\u0026utm_campaign=peerlyst_shared_post)\n- [Endpoint Detection of Remote Service Creation and PsExec](https://countercept.com/blog/endpoint-detection-of-remote-service-creation-and-psexec/) - Hunting for lateral movement with Event Tracing for Windows (ETW)\n\n### Hunting with AI\n- [10 ways to use ChatGPT for Threat Hunting](https://infosecwriteups.com/learn-10-ways-to-use-chatgpt-for-threat-hunting-right-now-9fab5507f3b8)\n- [ChatGPT for CTI Professionals](https://socradar.io/chatgpt-for-cti-professionals/)\n- [Complete ChatGPT Guide for DevSecOps: Top 20 Most Essential Prompts](https://levelup.gitconnected.com/complete-chatgpt-guide-for-devsecops-top-20-most-essential-prompts-ef21e0aa4830)\n- [ChatGPT Use Cases for CyberSecurity Folks](https://atrhein.medium.com/chatgpt-use-cases-for-cybersecurity-folks-c4ae83656b92)\n- [60 Chat GPT Prompts for Cyber Security by Experts](https://nextdoorsec.com/chat-gpt-prompts-for-cyber-security/)\n\n### Must Read\n- [Threat Hunting:Open Season on the Adversary](https://www.sans.org/reading-room/whitepapers/analyst/threat-hunting-open-season-adversary-36882)\n- [The Who, What, Where, When, Why and How of Effective Threat Hunting](https://www.sans.org/reading-room/whitepapers/analyst/who-what-where-when-effective-threat-hunting-36785)\n- [Incident Response is Dead... Long Live Incident Response](https://medium.com/@sroberts/incident-response-is-dead-long-live-incident-response-5ba1de664b95)\n- [Hunting, and Knowing What To Hunt For](http://windowsir.blogspot.cz/2015/06/hunting-and-knowing-what-to-huntnot-for.html)\n- [Cyber Hunting: 5 Tips To Bag Your Prey](http://www.darkreading.com/risk/cyber-hunting-5-tips-to-bag-your-prey/a/d-id/1319634?_mc=RSS_DR_EDT)\n- [A Simple Hunting Maturity Model](http://detect-respond.blogspot.cz/2015/10/a-simple-hunting-maturity-model.html)\n- [A Framework for Cyber Threat Hunting](http://sqrrl.com/media/Framework-for-Threat-Hunting-Whitepaper.pdf)\n- [Seek Evil, and Ye Shall Find: A Guide to Cyber Threat Hunting Operations](https://digitalguardian.com/blog/seek-evil-and-ye-shall-find-guide-cyber-threat-hunting-operations)\n- [A Guide to Cyber Threat Hunting Operations](https://www.infosecurity-magazine.com/opinions/a-guide-to-cyber-threat-hunting/)\n- [Inside 3 top threat hunting tools](http://www.networkworld.com/article/3150473/security/threat-hunting-tools-could-be-a-security-game-changer.html#slide13) - High level overview of Sqrrl, Infocyte and EndGame\n- [True Threat Hunting: more than just threats and anomalies](http://www.baesystems.com/en/cybersecurity/blog/true-threat-hunting#) - Some valid thoughts on what's needed for an effective Threat Hunting program\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FA3sal0n%2FCyberThreatHunting","html_url":"https://awesome.ecosyste.ms/projects/github.com%2FA3sal0n%2FCyberThreatHunting","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2FA3sal0n%2FCyberThreatHunting/lists"}