Atomic Red Team (opens in a new tab)
Why: Open library of portable, ATT&CK-mapped tests that security teams can run to check whether their detections actually catch real attacker behaviours.
Approaches and references for proactive hunting beyond alert triage.
5 current resources
Highest starting-point strength resources in this category.
Why: Open library of portable, ATT&CK-mapped tests that security teams can run to check whether their detections actually catch real attacker behaviours.
Why: Curated collection of hunting tools, methods and references — a practical starting point when building or refreshing a threat-hunting programme.
Why: Open library of Sigma detection rules that translate to many SIEM and EDR backends, accelerating consistent hunting and detection engineering across tools.
Showing 5 resources
Why: Open library of portable, ATT&CK-mapped tests that security teams can run to check whether their detections actually catch real attacker behaviours.
Why: Curated collection of hunting tools, methods and references — a practical starting point when building or refreshing a threat-hunting programme.
Why: Open library of Sigma detection rules that translate to many SIEM and EDR backends, accelerating consistent hunting and detection engineering across tools.
Why: Structured threat-hunting methodology that folds threat intelligence into hunt cycles, giving analysts a repeatable way to pursue targeted leads.
Why: Shared hunting framework that helps teams design detection and hunt workflows in a structured way, useful when building a repeatable threat-hunting practice.