Security lists for SOC/DFIR detections
Awesome Security lists for SOC/CERT/CTI
This page lists names, links and short descriptions. The original list on GitHub is the source and belongs to its authors.
Threat Hunting:
ThreatHunting Yara rules
Yara rules for Threat Hunting sessions
General
General
🔥 EricZimmerman Tools 🔥
An updated list of forensic tools created by Eric Zimmerman, an instructor for SANS institute.
arfifacts List - ForensicArtifacts
A free, community-sourced, machine-readable knowledge base of digital forensic artifacts.
SleuthKit
The Sleuth Kit® (TSK) is a library and collection of command line digital forensics tools that allow you to investigate volume and file system data. The library can be incorporated into larger digital forensics tools and the command line tools can be directly used to find evidence.
[OS] Remnux
Linux distribution and docker images for malware reverse engineering and analysis.
[OS] tsurugi
heavily customized Linux distribution that designed to support DFIR investigations, malware analysis and OSINT activities. It is based on Ubuntu 20.04(64-bit with a 5.15.12 custom kernel)
PSBits
Simple (relatively) things allowing you to dig a bit deeper than usual.
ThreatHunting Yara rules
Yara rules for Threat Hunting sessions
capa
detects capabilities in executable files. You run it against a PE, ELF, .NET module, or shellcode file and it tells you what it thinks the program can do.
[EVTX] Hayabusa
Hayabusa is a Windows event log fast forensics timeline generator and threat hunting tool created by the Yamato Security group in Japan.
[EVTX] WELA
Windows Event Log Analyzer aims to be the Swiss Army knife for Windows event logs.
[EVTX] APTHunter
APT-Hunter is Threat Hunting tool for windows event logs.
[EVTX / Auditd] Zircolite
A standalone and fast SIGMA-based detection tool for EVTX or JSON.
PersistenceSniper
Powershell module to hunt for persistence implanted in Windows machines.
Logon Tracer
Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.
Timeline Plaso
a Python-based backend engine for the tool log2timeline.
Timeline TimeSketch
Open source tool for collaborative forensic timeline analysis.
hollows hunter
Scans all running processes. Recognizes and dumps a variety of potentially malicious implants (replaced/implanted PEs, shellcodes, hooks, in-memory patches).
PE sieve
Scans a given process. Recognizes and dumps a variety of potentially malicious implants (replaced/injected PEs, shellcodes, hooks, in-memory patches).
RdpCacheStitcher
RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.
Searching strings - ripgrep
Better and faster grep. Recursively searches directories while respecting gitignore rules and skipping hidden/binary files.; Flavors: Rust (default), PCRE.
Kape
The tool allows collecting various predefined artifactgs using targets and modules, see KapeFiles which include persistence mechanisms, among others there's a collection of LNK files, scheduled task files and scheduled task listing or a WMI repository auditing module.
Velociraptor
Velociraptor is a tool for collecting host based state information using Velocidex Query Language (VQL) queries
[memory] MemProcFS
An easy and convenient way of accessing physical memory as files a virtual file system.
[memory] MemProcFS-Analyzer
PowerShell script utilized to simplify the usage of MemProcFS and to optimize your memory analysis workflow.
[memory] avml
A portable volatile memory acquisition tool for Linux.
[memory] Volatility
The volatile memory extraction framework (successor of Volatility)
[Image Mount] OSFMount
allows you to mount local disk image files (bit-for-bit copies of an entire disk or disk partition) in Windows as a physical disk or a logical drive
[Network] Network Miner
A network forensic tool for PCAP file analysis.
[Network] Wireshark
Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education. Wireshark is very similar to tcpdump, but has a graphical front-end, plus some integrated sorting and filtering options.
[Carving] Bulk Extractor
Computer forensics tool that scans a disk image, a file, or a directory of files and extracts useful information without parsing the file system or file system structures. Because of ignoring the file system structure, the program distinguishes itself in terms of speed and thoroughness.
[memory] Lime
Loadable Kernel Module (LKM), which allows the acquisition of volatile memory from Linux and Linux-based devices, formerly called DMD.
Windows artifacts
[Guide to the various Windows forensic artifacts]
[Linux] UAC
UAC (Unix-like Artifacts Collector) is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.
[Linux] EXT4 / XFS - fjta
Tool that analyzes Linux filesystem (ext4, XFS) journals (not systemd-journald logs), generates timelines, and detects suspicious activities
lists - aboutdfir.com
Collection of forensic resources for learning and research. Offers lists of certifications, books, blogs, challenges and more
Monitoring - Osquery
is a SQL powered operating system instrumentation, monitoring, and analytics framework.
[OSX Tools] mac_apt
Plugin based forensics framework for quick mac triage that works on live machines, disk images or individual artifact files.
General
chainabuse (for malicious owned crypto wallets address)
Report and search crypto scam addresses.
C2IntelFeeds
C2 intelligence feeds for threat hunting.
Volexity TI
sparkles: :gem:; This repository contains IoCs related to Volexity public threat intelligence blog posts.
Unit42 Articles IOC
IOCs and supporting data for Palo Alto Networks Unit 42 threat research articles, so indicators can be traced back to their write-up.
ESET Research IOC
eyes:; Collection of YARA and Snort rules from IOCs collected by ESET researchers. There's about a dozen YARA Rules to glean from in this repo, search for file extension .yar. This repository is seemingly updated on a roughly monthly interval. New IOCs are often mentioned on the ESET…
Cisco Talos IOC
IOCs from Cisco Talos.
UrlHaus
Community-driven repository for real-time malicious URL data, offering actionable threat intelligence to block phishing and malware.
vx-underground - Great Resource for Samples and Intelligence Reports
PL-CERT based open source MWDB python application holding a malware database containing every APT sample from 2010 and over 7.5M maliciousbinaries.
Ransomware.live
A monitoring ransomware's victims in near real-time.
General
General
PurpleTeam atomics
A red team attack techniques framework supporting also the MITRE ATT&CK persistence techniques, see e.g. T1044 "File System Permissions Weakness".
General
PurpleTeam atomics
A red team attack techniques framework supporting also the MITRE ATT&CK persistence techniques, see e.g. T1044 "File System Permissions Weakness".
redcanary Threat Detection report
Threat Detection Report (2026) - Analyzes the evolving cybersecurity landscape by examining over one hundred thousand confirmed threats across diverse infrastructure and identity environments. Key findings reveal that identity based attacks surged by 850 percent year over year, now accounting for…
Cyber Kill chain
Lockheed Martin's framework that outlines the 7 stages commonly observed in a cyber attack.
MITRE CAR
The Cyber Analytics Repository is a knowledge base of analytics developed by MITRE based on the Adversary Tactics, Techniques, and Common Knowledge (ATT&CK™) adversary model.
CVE Vuln Database
Dictionary of common names (i.e., CVE Identifiers) for publicly known security vulnerabilities.
General
Virustotal
VirusTotal, a subsidiary of Google, is a free online service that analyzes files and URLs enabling the identification of viruses, worms, trojans and other kinds of malicious content detected by antivirus engines and website scanners. At the same time, it may be used as a means to detect false…
SpamHaus
Lookup Reputation Checker.
AbuseIPDB
AbuseIPDB is a project dedicated to helping combat the spread of hackers, spammers, and abusive activity on the internet.
Malwarebazaar
Share malware samples for research purposes.
dnsdumpster
DNSdumpster.com is a FREE domain research tool that can discover hosts related to a domain. Finding visible hosts from the attackers perspective is an important part of the security assessment process.
nslookup.io
Find all DNS records for a domain name using this online tool
cloudfare URL scan
URL scanner by Cloudflare for security analysis.
shodan
Shodan is a search engine that lets users search for various types of servers connected to the internet using a variety of filters. Some have also described it as a search engine of service banners, which are metadata that the server sends back to the client.
Onyphe
ONYPHE is an Attack Surface Management & Attack Surface Discovery solution built as a Cyber Defense Search Engine. We scan the entire Internet and Dark Web for exposed assets and crawl the links just like a Web search engine. Our data is searchable with a Web form or directly from our numerous APIs.
haveibeenpwned
Checks if your credentials (Email address or Password) have been compromised in a data breach. See also Firefox Monitor.
Censys
Search Engine for every server on the Internet to reduce exposure and improve security
cybergordon (URL reputation check)
CyberGordon is a threat intelligence search engine. It leverages 30+ sources.
threatminer
ThreatMiner is a threat intelligence portal designed to enable analysts to research under a single interface.
urlscan
urlscan.io is a free service to scan and analyse websites. When a URL is submitted to urlscan.io, an automated process will browse to the URL like a regular user and record the activity that this page navigation creates.
urlquery
Free URL Scanner.
cloudfare scanner
Global Internet traffic, attack, and technology trends and insights
scamsearch.io
search to find phone, email, profile if is tobe a scammer.
scamdb.net
Report and Search Online Scams
urlvoid
Analyzes a website through multiple blacklist engines and online reputation tools to facilitate the detection of fraudulent and malicious websites.
urldna.io
Unleash website insights! urldna.io analyzes data, monitors brands and exposes security risks
url checkphish
An online tool that finds registered domain typosquats and analyzes them for suspicious activity.
ipvoid
IP address reputation and blacklist check.
mxtoolbox mail header
Email headers are present on every email you receive via the Internet and can provide valuable diagnostic information like hop delays, anti-spam results and more. If you need help getting copies of your email headers
pulsedive
A partially free website research tool. Collects detailed information about IP, whois, ssl, dns, ports, threats reports, geolocation, cookies, metadata (fb app id etc). Make screenshots and many others
threatbook
One step ahead of your adversary with high-fidelity, efficient and actionable cyber threat intelligence
web archive
Explore more than 702 billion web pages saved over time
IBM X-Force Exchange
Threat intelligence sharing platform enabling research on security threats, aggregation of intelligence, and collaboration with peers
AlienVault OTX
Open Threat Exchange is the neighborhood watch of the global intelligence community. It enables private companies, independent security researchers, and government agencies to openly collaborate and share the latest information about emerging threats, attack methods, and malicious actors,…
url tiny-scan
Free URL inspection online tool: ip, location, desktop/mobile screenshots, number of links, javascript files and stylesheets, technology profile, number of request and bytes transferred and more.
certificates - crt.sh
Enter an Identity (Domain Name, Organization Name, etc), a Certificate Fingerprint (SHA-1 or SHA-256) or a crt.sh ID to search certificate(s) by @crtsh.
site web-check
Get detailed report about IP or domain: Location SSL Info Headers Domain and host names Whois DNS records Crawl riles Cookies Server Info Redirects Server status TXT Config
validin.com
Website and API to search current and historical DNS records for free
Malware-Traffic-Analysis (PCAP files)
A large collection of malicious PCAP files that can be used to practice packet capture skills.
redhuntlabs
This Custom Search Tool by @RedHuntLabs Team looks for keywords/strings in following Online IDEs, Paste(s) sites and Code Sharing Platforms.
whois domaintools
Go beyond ordinary Whois to discover the people or organizations behind a domain name or IP address.
OUI mac address lookup
An online OUI lookup for searching vendors of MAC addresses.
macvendorlookup
Look up the vendor for a specific MAC Address
abuse.ch
ZeuS Tracker / SpyEye Tracker / Palevo Tracker / Feodo Tracker tracks Command&Control servers (hosts) around the world and provides you a domain- and an IP-blocklist.
waybackmachine
Internet Archive
asnlookup
Quickly lookup updated information about specific Autonomous System Number (ASN), Organization, CIDR, or registered IP addresses (IPv4 and IPv6) among other relevant data
SecurityTrail
Historical and current WHOIS, historical and current DNS records, similar domains, certificate information and other domain and IP related API and tools.
ZommEye
ZoomEye is a cyberspace search engine for IPs, domains, internet asset discovery, and exposure analysis of servers, routers, and webcams.
Norton lookup
Look up a site, Get our rating
Talos Intelligence lookup
IP and Domain Reputation Center for real-time threat detection
General
triage
Fully automated solution for high-volume malware analysis using advanced sandboxing technology
filescan.io
Static malware analysis, VBA/Powershell/VBS/JS Emulation
Hybrid Analysis
Free malware analysis service for the community that detects and analyzes unknown threats using a unique Hybrid Analysis technology
Virustotal
VirusTotal, a subsidiary of Google, is a free online service that analyzes files and URLs enabling the identification of viruses, worms, trojans and other kinds of malicious content detected by antivirus engines and website scanners. At the same time, it may be used as a means to detect false…
kaspersky opentip
Scan files, domains, IP addresses, and URLs for threats, malware, viruses
General
CyberChef
collection of more than a hundred online #tools for automating a wide variety of tasks (string coding, text comparison, double-space removal)
JS deobfuscator
HTML/JS deobfuscator
regex101
Best free and best web-based tester.; Flavors: Java, JavaScript, .NET, PCRE, RE2, Rust, and emulates Python.; Includes regex debugger (PCRE only).
UrlEncode.org
온라인 url 인코더/디코더
RegExr
[GitHub] - Best open source tester.; Flavors: JavaScript, PCRE.; Languages: 🇺🇸, 🇨🇳 (fork).
Pretty Diff
available
mxtoolbox mail header
Email headers are present on every email you receive via the Internet and can provide valuable diagnostic information like hop delays, anti-spam results and more. If you need help getting copies of your email headers
uncoder
An online translator for SIEM saved searches, filters, queries, API requests, correlation and Sigma rules
DeHashed
DeHashed helps prevent ATO with our extensive data set & breach notification solution. Match employee and consumer logins against the world’s largest repository of aggregated publicly available assets leaked from third-party breaches. Secure passwords before criminals can abuse stolen information,…
General
MITRE Datasources
Data source objects added to MITRE ATT&CK as part of v10.
LOTS
Cataloging how cyber attackers abuse legitimate platforms like GitHub or Google Docs to host malware, C2, or exfiltrate data
loldrivers
Open-source project that brings together vulnerable, malicious, and known malicious Windows drivers
WTFBIN
Catalogue benign applications that exhibit suspicious behavior. These binaries can emit noise and false positives in threat hunting and automated detections
Splunk Rules
and Analytic stories
Elastic Rules
Elastic's detection rules written natively for the Elastic SIEM. Can easily be converted for use by other SIEMs using Uncoder.
KQL Hunting Queries
A list of endpoint detections and hunting queries for Microsoft Defender for Endpoint, Defender For Identity, and Defender For Cloud Apps.
LOLOLFarm
A collection of resources for thriving off the land.
General
Cisco Talos
The threat intelligence organization at the center of the Cisco Security portfolio
Detection engineering weekly
A newsletter dedicated to news and how-tos for Detection Engineering.
DFIR weekly news
A weekly roundup of digital forensics and incident response news.
krebsonsecurity feed
Investigative reporting on cybercrime, breaches, and threat actors.
tl;dr sec newsletter
. A weekly distillation of the best security tools, blog posts, and conference talks, covering AppSec, cloud and container security, DevSecOps, and more.
General
Exploitation - Defcon Talks
+ https://media.defcon.org/
General
darknetdiaries
Description: Darknet Diaries explores true stories from the dark side of the Internet. Go behind the hack and hear stories from the "cyber" front lines. Whether you're just curious how hacks happen or are a seasoned Infosec pro, you'll learn something new in an entertaining format.; Host: Jack…
risky.biz
by Patrick Gray
Internet Storm Center sans podcast
Description: Stormcasts are daily 5-10 minute information security threat updates.; Host: Dr. Johannes Ullrich @johullrich; Frequency: Daily; Runtime: Regularly 5 mins
General
General
HackTheBox
OSINT challenges in CTF format.
Pentestlab
PentesterLab - Hands on labs to understand and exploit simple and advanced web vulnerabilities.
Root-Me
Hundreds of challenges are available to train yourself in different and not simulated environments
General
The Art of Memory Forensics: Detecting Malware and Threats in Windows, Linux, and Mac Memory
Detecting Malware and Threats in Windows, Linux, and Mac Memory.
Applied Incident Response
Steve Anson's book on Incident Response.
Crafting the InfoSec Playbook: Security Monitoring and Incident
by Jeff Bollinger, Brandon Enright and Matthew Valites.
PTFM: Purple Team Field Manual
+ PTFM: Purple Team Field Manual v2
Linux insides
A book-in-progress about the Linux kernel and its insides.
General
lists - aboutdfir.com
Collection of forensic resources for learning and research. Offers lists of certifications, books, blogs, challenges and more
Exploitation - PayloadsAllTheThings
An API key is a unique identifier that is used to authenticate requests associated with your project. Some developers might hardcode them or leave it on public shares.
Linux - EBPF docs
Providing technical documentation for eBPF.
Logs - Microsoft Defender for Cloud Alert References
A list of all Azure Security for Cloud Alerts, their descriptions, and associated data sources.
Logs - Microsoft Defender XDR Schemas
To help with multi-table queries, you can use the advanced hunting schema, which includes tables and columns with event information and details about devices, alerts, identities, and other entity types.
SOC - explain shell command arguments
this site will help you quickly understand terminal commands-lines from articles, manuals, and tutorials
General
LAB automation - Azure - AzureGoat
A Damn Vulnerable Azure Infrastructure
SandBox - cuckoo
Cuckoo Sandbox is an automated dynamic malware analysis system.
SandBox - CAPEv2
eyes:; Rules from various authors bundled with the Config And Payload Extraction Cuckoo Sandbox extension (see next section).
SandBox - Malice (Virustotal self hosted clone)
Massively scalable malware analysis framework.
Detection platform - wazuh
Wazuh is a free and open source platform used for threat prevention, detection, and response. It is capable of monitoring file system changes, system calls and inventory changes.
Deployment - ansible
Ansible is a radically simple IT automation platform that makes your applications and systems easier to deploy. Avoid writing scripts or custom code to deploy and update your applications — automate in a language that approaches plain English, using SSH, with no agents to install on remote systems.
Network Logs - maltrail
A malicious traffic detection system, utilizing publicly available (black)lists containing malicious and/or generally suspicious trails and featuring an reporting and analysis interface.
LInux Logs - ossec
OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.
Linux Logs - ecapture (SSL/TLS)
Capturing SSL/TLS plaintext without a CA certificate using eBPF. Supported on Linux/Android kernels for amd64/arm64.
Linux Logs - tracee
A runtime security and forensics tool for Linux which uses eBPF technology to trace the system and applications at runtime, and analyze collected events to detect suspicious behavioral patterns.
CTI - OpenCTI
Open cyber threat intelligence platform.
CTI - MISP
Threat intelligence platform including indicators, threat intelligence, malware samples and binaries. Includes support for sharing, generating, and validating YARA signatures.
IR platform - iris-web
IRIS is a web collaborative platform for incident response analysts allowing to share investigations at a technical level.
IR platform - FIR
Cybersecurity incident management platform designed with agility and speed in mind. It allows for easy creation, tracking, and reporting of cybersecurity incidents and is useful for CSIRTs, CERTs and SOCs alike.
Log samples - Splunk Attack range
A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data into Splunk.
IT - Remote connections manager - xpipe
Access your entire server infrastructure from your local desktop
Endpoint Security - Linux Hardening - lynis
Lynis - Security auditing tool for Linux, macOS, and UNIX-based systems. Assists with compliance testing (HIPAA/ISO27001/PCI DSS) and system hardening. Agentless, and installation optional..
General
chmod calculator
Calculate the octal numeric or symbolic value for a set of file or folder permissions in #Linux servers. Check the desired boxes or directly enter a valid numeric value to see its value in other format
10 minute mail
Disposable mail for 10 min.
General
Related lists in Security
See categoryAwesome-Selfhosted
awesome-selfhosted/awesome-selfhosted
A list of Free Software network services and web applications which can be hosted on your own servers
Awesome Hacker Search Engines
edoardottt/awesome-hacker-search-engines
A curated list of awesome search engines useful during Penetration testing, Vulnerability assessments, Red/Blue Team operations, Bug Bounty and more
Awesome Privacy
lissy93/awesome-privacy
🦄 A curated list of privacy & security-focused software and services
Awesome Bug Bounty Tools
vavkamil/awesome-bugbounty-tools
A curated list of various bug bounty tools
android-security-awesome
ashishb/android-security-awesome
A collection of android security related resources
Awesome Web Security
qazbnm456/awesome-web-security
🐶 A curated list of Web Security materials and resources.