A curated collection of updated security detection lists and resources designed to support SOC, CERT, and CTI teams in threat hunting and network monitoring.
Awesome Security lists for SOC/CERT/CTI
This repository serves as a comprehensive dataset for security analysts and threat hunters to enhance detection capabilities by leveraging curated lists of suspicious indicators such as TLDs, ASNs, user agents, and Windows services. It is primarily used by SOC, CERT, and CTI professionals to improve threat intelligence, conduct OSINT investigations, and facilitate network monitoring and detection workflows.
This repository is a dataset and resource collection rather than an executable tool; users should integrate these lists into their existing detection platforms or SIEMs. Regularly updating the lists is recommended to maintain effectiveness against emerging threats. Familiarity with threat hunting concepts and detection engineering will maximize the utility of these resources.