MITRE ATT&CK Navigator(source code) - The ATT&CK Navigator is designed to provide basic navigation and annotation of ATT&CK matrices, something that people are already doing today in tools like Excel.
HELK - A Hunting ELK (Elasticsearch, Logstash, Kibana) with advanced analytic capabilities.
osquery - An operating system instrumentation framework for Windows, OS X (macOS), Linux, and FreeBSD. It exposes an operating system as a high-performance relational database.
osquery-configuration - A repository for using osquery for incident detection and response.
Zentral - Combines osquery's powerful endpoint inventory features with a flexible notification and action framework. This enables one to identify and react to changes on OS X and Linux clients.
DetectionLab - Vagrant & Packer scripts to build a lab environment complete with security tooling and logging best practices.
Sysmon-DFIR - Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.
go-audit - An alternative to the auditd daemon that ships with many distros.
sqhunter - A simple threat hunting tool based on osquery, Salt Open and Cymon API.
RedHunt-OS - A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment.
Oriana - Lateral movement and threat hunting tool for Windows environments built on Django comes Docker ready.
Brosquery - A module for osquery to load Bro logs into tables
Kolide Fleet - A flexible control server for osquery fleets
DeepBlueCLI - A PowerShell Module for Hunt Teaming via Windows Event Logs
Invoke-ATTACKAPI - A PowerShell script to interact with the MITRE ATT&CK Framework via its own API.
Unfetter - A reference implementation provides a framework for collecting events (process creation, network connections, Window Event Logs, etc.) from a client machine and performing CAR analytics to detect potential adversary activity.
Flattened MITRE ATT&CK Matrix - It contains all matrix categories mapped to techniques with examples of application by software or threat actor groups.
SANS Summit Archives (DFIR, Cyber Defense) - Threat hunting, Blue Team and DFIR summit slides
Bro-Osquery - Large-Scale Host and Network Monitoring Using Open-Source Software
Frameworks
MITRE ATT&CK - A curated knowledge base and model for cyber adversary behavior, reflecting the various phases of an adversary’s lifecycle and the platforms they are known to target.
MITRE CAR - The Cyber Analytics Repository (CAR) is a knowledge base of analytics developed by MITRE based on the Adversary Tactics, Techniques, and Common Knowledge (ATT&CK™) adversary model.
A Simple Hunting Maturity Model - The Hunting Maturity Model describes five levels of organizational hunting capability, ranging from HMM0 (the least capability) to HMM4 (the most).
The Pyramic of Pain - The relationship between the types of indicators you might use to detect an adversary's activities and how much pain it will cause them when you are able to deny those indicators to them.
Cyber Kill Chain - It is part of the Intelligence Driven Defense® model for identification and prevention of cyber intrusions activity. The model identifies what the adversaries must complete in order to achieve their objective.
The DML Model - The Detection Maturity Level (DML) model is a capability maturity model for referencing ones maturity in detecting cyber attacks.
"Awesome Detection" Collection - A collection of tweets about threat detection, hunting, DFIR, and read teaming techniques that can help you create detection logics.
A curated list of awesome adversary simulation resources
Tools
MITRE CALDERA - An automated adversary emulation system that performs post-compromise adversarial behavior within Windows Enterprise networks.
APTSimulator - A Windows Batch script that uses a set of tools and output files to make a system look as if it was compromised.
Atomic Red Team - Small and highly portable detection tests mapped to the Mitre ATT&CK Framework.
Network Flight Simulator - flightsim is a lightweight utility used to generate malicious network traffic and help security teams to evaluate security controls and network visibility.
Metta - A security preparedness tool to do adversarial simulation.
Red Team Automation (RTA) - RTA provides a framework of scripts designed to allow blue teams to test their detection capabilities against malicious tradecraft, modeled after MITRE ATT&CK.
CACTUSTORCH - Payload Generation for Adversary Simulations.
DumpsterFire - A modular, menu-driven, cross-platform tool for building repeatable, time-delayed, distributed security events.
Empire(website) - A PowerShell and Python post-exploitation agent.
PowerSploit - A PowerShell Post-Exploitation Framework.
RedHunt-OS - A Virtual Machine for Adversary Emulation and Threat Hunting. RedHunt aims to be a one stop shop for all your threat emulation and threat hunting needs by integrating attacker's arsenal as well as defender's toolkit to actively identify the threats in your environment.