Back to Topics Directory
Topic Hub

#threat-hunting (27 Repositories)

Ranked open-source repositories tagged with #threat-hunting, scored by pull request acceptance likelihood and maintainer engagement velocity.

Topic Avg Merge Rate

22.1%

Avg Review Latency

38.0h

Filter by language

27 repositories tagged #threat-hunting

S TierShell 4.9k

Security-Onion-Solutions/securityonion

Security Onion is a free and open platform for threat hunting, enterprise security monitoring, and log management. It includes our own interfaces for alerting, dashboards, hunting, PCAP, detections, and case management. It also includes other tools such as osquery, CyberChef, Elasticsearch, Logstash, Kibana, Suricata, and Zeek.

94.4%
Merge Rate
4d
First Review
100%
1st-Timers
6
Maintainers
A TierHTML 339

THORCollective/HEARTH

A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters to share knowledge, collaborate on techniques, and advance the field of threat hunting.

100.0%
Merge Rate
4d
First Review
100%
1st-Timers
2
Maintainers
A TierPython 636

MISP/misp-galaxy

Clusters and elements to attach to MISP events or attributes (like threat actors)

96.3%
Merge Rate
12d
First Review
100%
1st-Timers
2
Maintainers
B TierPython 184

fhightower/ioc-finder

Simple, effective, and modular package for parsing observables (indicators of compromise (IOCs), network data, and other, security related information) from text. It uses grammars rather than regexes which makes it more readable, maintainable, and hackable. Explore our interactive documentation here: https://hightower.space/ioc-finder/

83.3%
Merge Rate
7d
First Review
100%
1st-Timers
1
Maintainers
A TierPython 261 1 GFIs

Vigil-SOC/vigil

Vigil: the open source AI SOC (agentic SOC). 13 specialized AI agents, 30+ MCP integrations, 7,200+ detection rules. Apache 2.0.

66.7%
Merge Rate
14h
First Review
60%
1st-Timers
14
Maintainers
A TierPHP 6.5k

MISP/MISP

MISP (core software) - Open Source Threat Intelligence and Sharing Platform

67.4%
Merge Rate
16h
First Review
67%
1st-Timers
38
Maintainers
B TierC 6.6k

OISF/suricata

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.

15.3%
Merge Rate
4h
First Review
12%
1st-Timers
18
Maintainers
B TierPython 2.7k

elastic/detection-rules

72.7%
Merge Rate
4d
First Review
50%
1st-Timers
21
Maintainers
D TierPython 869

Bert-JanP/Open-Source-Threat-Intel-Feeds

This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.

0.0%
Merge Rate
9d
First Review
0%
1st-Timers
1
Maintainers
D TierPython 170

mthcht/ThreatIntel-Reports

Raw data from Threat Intelligence Reports with automatic reports collection and keyword search across thousands of reports

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierMulti-language 4.7k

0x4D31/awesome-threat-detection

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierGo 234

boringtools/git-alerts

Tool to detect and monitor GitHub org users' public repositories for secrets and sensitive files

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 202

jepayneMSFT/WEFFLES

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierGo 440

utkusen/baitroute

A web honeypot library to create vulnerable-looking endpoints to detect and mislead attackers

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 489

LearningKijo/SecurityResearcher-Note

Cover various security approaches to attack techniques and also provides new discoveries about security breaches.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierMAMakefile 643

chainguard-dev/osquery-defense-kit

Production-ready detection & response queries for osquery

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 795

darkquasar/AzureHunter

A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierRust 432

SitinCloud/Owlyshield

Owlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact).

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierHTML 385

cloudtracer/ThreatPinchLookup

Documentation and Sharing Repository for ThreatPinch Lookup Chrome & Firefox Extension

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPOPowerShell 357

olafhartong/ATTACKdatamap

A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierRust 389

pandaadir05/ghost

Detects process injection and memory manipulation used by malware. Finds RWX regions, shellcode patterns, API hooks, thread hijacking, and process hollowing. Built in Rust for speed. Includes CLI and TUI interfaces.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 2.7k

osintbrazuca/osint-brazuca

Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 4.6k

OTRF/ThreatHunter-Playbook

A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 983

atenreiro/opensquat

openSquat is an open-source tool that detects look-alike domains impersonating your brand, by scanning newly registered domains daily.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierPython 103

helixmap/sigwood

Local-first, transparent threat hunting for the logs you already have: Zeek, Pi-hole, syslog, CloudTrail. Named technique behind every finding. No SIEM, no agent, no black box.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierShell 365

MalwareSamples/Malware-Feed

Bringing you the best of the worst files on the Internet.

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
D TierHTML 367

decal/werdlists

:keyboard: Wordlists, Dictionaries and Other Data Sets for Writing Software Security Test Cases

0.0%
Merge Rate
-
First Review
0%
1st-Timers
0
Maintainers
Best Threat-hunting Open Source Repositories & C-Rank™ | GetMerged