# mthcht/awesome-lists

Awesome Security lists for SOC/CERT/CTI

Repository: https://github.com/mthcht/awesome-lists
Canonical: https://ross.abutalabs.com/products/awesome-lists
Language: YARA
License: MIT
License Family: permissive
Topics: blueteam, hacktools, redteam, security, soc, awesome-list, cti, ioc, blueteam-tools, detection, detection-engineering, dfir, incident-response, iocs, ir, siem, threat-hunting, threat-intelligence, ransomware, rmm
Last push: 2026-08-26T20:44:44+00:00

## Health v2 (maintenance only)
Score: 67/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 99, release rhythm 8, longevity 97
- inputs: {"age_days": 1361, "days_push": 7, "days_rel": 550, "gap_med": null, "n_releases_24m": 1}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1892, forks 235 (observed 2026-08-28T04:05:49.531886+00:00)

## What it is
A curated collection of security detection lists and resources for SOC, CERT, and CTI teams, including suspicious TLDs, ASNs, named pipes, Windows services, and threat hunting keywords. It aggregates continuously updated CSV lists, YARA rules, and hunting guides for building SIEM detections.

## Use cases
- find lists of suspicious TLDs and ASNs for SIEM detections
- threat hunt for suspicious Windows services and named pipes
- get YARA rules for threat hunting keywords
- build detection rules for phishing and C2 activity
- curated security resources for SOC and DFIR teams
- detect ransomware and hacktool activity in logs

## When to choose
- you are a SOC analyst or detection engineer needing curated indicator lists
- you want continuously updated suspicious TLD, ASN, and service name lists
- you need threat hunting keywords and YARA rules for purple teaming

## When to avoid
- you need a runnable detection engine rather than reference lists
- you want automated SIEM integration out of the box

## Facets
- artifact type: dataset
- maturity: active
- function: security, monitoring, search-engine
- domain: security, awesome-lists
- platform: self-hosted, cross-platform
- tags: soc, dfir, cti, siem, threat-hunting, ioc, detection-engineering, yara, incident-response, redteam, blueteam, threat-intelligence

## Member repositories
- mthcht/awesome-lists (main) score 67

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:49.531886+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:12:57.886861+00:00, confidence not recorded.
  - readme: https://github.com/mthcht/awesome-lists (fetched 2026-08-28T04:05:49.531886+00:00, sha d9677a1f46da)
- Data as of 2026-08-30T08:39:29.467469+00:00.
