Awesome list of keywords and artifacts for Threat Hunting sessions
-
Updated
Aug 4, 2025 - PowerShell
Awesome list of keywords and artifacts for Threat Hunting sessions
Purpleteam scripts simulation & Detection - trigger events for SOC detections
Capture all events across all logs produced during the running of a particular exploit/script. Search and filter events
Hayabusa to the SIEM made easy
Applied SOC Analysis and Incident Response documentation covering endpoint forensics, network traffic analysis (PCAP), and detection engineering. Demonstrating analyst-level investigative methodology using Splunk, Wireshark, and Sysinternals.
LLMNR/NBT-NS Detection
Add a description, image, and links to the detection-engineering topic page so that developers can more easily learn about it.
To associate your repository with the detection-engineering topic, visit your repo's landing page and select "manage topics."