Python threat-hunting

Open-source Python projects categorized as threat-hunting

Top 21 Python threat-hunting Projects

  • dnstwist

    Domain name permutation engine for detecting homograph phishing attacks, typo squatting, and brand impersonation

  • Project mention: Have I Been Squatted? | news.ycombinator.com | 2023-11-27
  • ThreatHunter-Playbook

    A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • IntelOwl

    IntelOwl: manage your Threat Intelligence at scale

  • Project mention: Monthly Security Checklist | /r/msp | 2023-06-25
  • malwoverview

    Malwoverview is a first response tool used for threat hunting and offers intel information from Virus Total, Hybrid Analysis, URLHaus, Polyswarm, Malshare, Alien Vault, Malpedia, Malware Bazaar, ThreatFox, Triage, InQuest and it is able to scan Android devices against VT.

  • APT_REPORT

    Interesting APT Report Collection And Some Special IOC

  • yeti

    Your Everyday Threat Intelligence

  • beagle

    Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs. (by yampelo)

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
  • APT-Hunter

    APT-Hunter is Threat Hunting tool for windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity

  • Project mention: APT-Hunter: APT-Hunter is Threat Hunting tool for Windows event logs which made by purple team mindset to provide detect APT movements hidden in the sea of windows event logs to decrease the time to uncover suspicious activity | /r/blueteamsec | 2023-05-07
  • threathunting

    A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

  • Hunting-Queries-Detection-Rules

    KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

  • Project mention: Advanced Hunting queries every admin should use | /r/DefenderATP | 2023-05-29
  • Watcher

    Watcher - Open Source Cybersecurity Threat Hunting Platform. Developed with Django & React JS. (by Felix83000)

  • CyberThreatHunting

    A collection of resources for Threat Hunters - Sponsored by Falcon Guard

  • ThreatIngestor

    Extract and aggregate threat intelligence.

  • opensquat

    The openSquat is an open-source tool for detecting domain look-alikes by searching for newly registered domains that might be impersonating legit domains.

  • Project mention: Have I Been Squatted? | news.ycombinator.com | 2023-11-27

    A different solution that runs locally is opensquat.

    https://github.com/atenreiro/opensquat

  • Scrummage

    The Ultimate OSINT and Threat Hunting Framework

  • misp-galaxy

    Clusters and elements to attach to MISP events or attributes (like threat actors)

  • Project mention: Foreign Travel Risks | /r/cybersecurity | 2023-04-26

    MISP Threat Actor Galaxy

  • kestrel-lang

    Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.

  • threatbus

    🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.

  • malware-ioc

    This repository contains indicators of compromise (IOCs) of our various investigations. (by prodaft)

  • Project mention: PTI-257 Group Indicators of Compromise (IOCs) - PTI-257 consists of former Wizard Spider actors who are publicly known for the various malware variants they use (Ryuk, Trickbot, and Conti, among others) | /r/blueteamsec | 2023-09-14
  • evtx-hunter

    evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.

  • MISP-tools

    Import CrowdStrike Threat Intelligence into your instance of MISP

  • SaaSHub

    SaaSHub - Software Alternatives and Reviews. SaaSHub helps you find the best software and product alternatives

    SaaSHub logo
NOTE: The open source projects on this list are ordered by number of github stars. The number of mentions indicates repo mentiontions in the last 12 Months or since we started tracking (Dec 2020).

Python threat-hunting related posts

Index

What are some of the best open-source threat-hunting projects in Python? This list will help you:

Project Stars
1 dnstwist 4,535
2 ThreatHunter-Playbook 3,866
3 IntelOwl 3,103
4 malwoverview 2,700
5 APT_REPORT 2,175
6 yeti 1,626
7 beagle 1,250
8 APT-Hunter 1,144
9 threathunting 1,102
10 Hunting-Queries-Detection-Rules 993
11 Watcher 795
12 CyberThreatHunting 792
13 ThreatIngestor 781
14 opensquat 648
15 Scrummage 488
16 misp-galaxy 480
17 kestrel-lang 273
18 threatbus 254
19 malware-ioc 196
20 evtx-hunter 137
21 MISP-tools 31

Sponsored
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com