Back to rankings

mthcht/awesome-lists

YARA

Awesome Security lists for SOC/CERT/CTI

blueteamhacktoolsredteamsecuritysocawesome-listctiiocblueteam-toolsdetectiondetection-engineeringdfir
Star Growth
Stars
1.8k
Forks
212
Weekly Growth
โ€”
Issues
17
5001k1.5k
Dec 2022Feb 2024May 2025Jul 2026
README

Security lists for SOC/DFIR detections Awesome

dt

๐Ÿพ Threat Hunting:

ThreatHunting searches

๐Ÿ“‚ My Detection Lists

I regularly update most of these lists after each tool i analyze in my detection keywords project

Other Lists

๐Ÿ›ก๏ธ DFIR:

๐Ÿšซ IOC Feeds/Blacklists:

๐Ÿ™ Github

๐Ÿ“Š TI TTP/Framework/Model/Trackers

๐Ÿ•ต๏ธโ€โ™‚๏ธ Investigation

๐Ÿ“Š TI checks

๐Ÿ”ฌ Sandbox / Emulation

๐Ÿงฉ Data manipulation

๐Ÿ“ก Detection Resources

๐ŸŒ Security News

๐Ÿ“บ Youtube/Twitch channels

๐ŸŽ™๏ธ Podcasts

๐Ÿ’ฌ Discord /Slack channels

๐Ÿ“š Training

DFIR

SOC

Offensive

Challenges

RE / Malware Analysis / Deep Dive

๐Ÿ“š Books

DFIR

Malware Anaysis

SOC

Deep Dive

Exploitation

AI

๐Ÿ“š Knowledge sites

๐Ÿงช LAB

๐Ÿ“ฆ Others

Content creation

๐Ÿท๏ธ Bookmarks

  • โญ Bookmarks with all my lists to import in your browser (updated automatically) UPDATE Bookmarks
Related repositories
chaitin/SafeLine

SafeLine is a self-hosted WAF(Web Application Firewall) / reverse proxy to protect your web apps from attacks and exploits.

GoGo ModulesGNU General Public License v3.0firewallhttp-flood
ly.safepoint.cloud/fUxS0GW
21.9k1.4k
laramies/theHarvester

E-mails, subdomains and names Harvester - OSINT

PythonPyPIosintsubdomain-enumeration
edge-security.com
16.9k2.5k
GTFOBins/GTFOBins.github.io

GTFOBins is a curated list of Unix-like executables that can be used to bypass local security restrictions in misconfigured systems.

YAMLGNU General Public License v3.0post-exploitationlinux
gtfobins.org
13.5k1.6k
LOLBAS-Project/LOLBAS

Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)

XSLTGNU General Public License v3.0lolbinslolscripts
lolbas-project.github.io
8.7k1.2k
yaklang/yakit

Cyber Security ALL-IN-ONE Platform

TypeScriptnpmGNU Affero General Public License v3.0redteamredteam-tools
7.6k819
ihebski/DefaultCreds-cheat-sheet

One place for all the default credentials to assist the Blue/Red teamers identifying devices with default password ๐Ÿ›ก๏ธ

PythonPyPIMIT Licenseinfosecdefault-password
pypi.org/project/DefaultCreds_cheat_sheet/
6.7k782
decalage2/awesome-security-hardening

A collection of awesome security hardening guides, tools and other resources

awesome-listsecurity
6.5k677
rmusser01/Infosec_Reference

An Information Security Reference That Doesn't Suck; https://rmusser.net/git/admin-2/Infosec_Reference for non-MS Git hosted version.

CSSnpmMIT Licenseinfosecinfosec-reference
rmusser.net/docs
6k1.2k
madhuakula/kubernetes-goat

Kubernetes Goat is a "Vulnerable by Design" cluster environment to learn and practice Kubernetes security using an interactive hands-on playground ๐Ÿš€

HTMLMIT Licensekubernetesvulnerable-app
madhuakula.com/kubernetes-goat
5.7k1k
ffffffff0x/1earn

ffffffff0x ๅ›ข้˜Ÿ็ปดๆŠค็š„ๅฎ‰ๅ…จ็Ÿฅ่ฏ†ๆก†ๆžถ,ๅ†…ๅฎนๅŒ…ๆ‹ฌไธไป…้™ไบŽ webๅฎ‰ๅ…จใ€ๅทฅๆŽงๅฎ‰ๅ…จใ€ๅ–่ฏใ€ๅบ”ๆ€ฅใ€่“้˜Ÿ่ฎพๆ–ฝ้ƒจ็ฝฒใ€ๅŽๆธ—้€ใ€Linuxๅฎ‰ๅ…จใ€ๅ„็ฑป้ถๆœบwritup

C++markdown-articlelinux-learning
home.ffffffff0x.com
5.7k1.3k
A-poc/BlueTeam-Tools

Tools and Techniques for Blue Team / Incident Response

blue-teamblueteam
4.3k653
snooppr/snoop

Snoop โ€” ะธะฝัั‚ั€ัƒะผะตะฝั‚ ั€ะฐะทะฒะตะดะบะธ ะฝะฐ ะพัะฝะพะฒะต ะพั‚ะบั€ั‹ั‚ั‹ั… ะดะฐะฝะฝั‹ั… (OSINT world)

PythonPyPIOtherosinttermux
github.com/snooppr/snoop/releases
4k453