# 0x4D31/awesome-threat-detection

✨ A curated list of awesome threat detection and hunting resources 🕵️‍♂️

Repository: https://github.com/0x4D31/awesome-threat-detection
Canonical: https://ross.abutalabs.com/products/awesome-threat-detection
Homepage: https://0x4d31.github.io/awesome-threat-detection/
License Family: other
Topics: awesome, awesome-list, threat-hunting, security, detection, threat-detection, incident-response
Last push: 2026-01-05T12:27:34+00:00

## Health v2 (maintenance only)
Score: 59/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 60, release rhythm 35, longevity 100
- inputs: {"age_days": 3154, "days_push": 240, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 4710, forks 757 (observed 2026-08-28T04:08:57.378253+00:00)

## What it is
A curated awesome list of threat detection and threat hunting resources, including tools, detection rules, datasets, research papers, trainings, labs, and threat simulation materials. It serves as a reference index for security practitioners building detection and hunting capabilities.

## Use cases
- find tools for threat hunting in my environment
- learn about threat detection frameworks and resources
- find detection rule repositories for SIEM or EDR
- build a security detection lab for practice
- find adversary emulation and threat simulation tools
- discover trainings and labs for becoming a threat hunter
- find research papers and blogs on detection engineering

## When to choose
- you need a starting point to discover threat detection and hunting tools and learning resources
- you are building a detection engineering or threat hunting practice and want curated references
- you want links to datasets, detection rules, and labs in one place

## When to avoid
- you need a working detection product rather than a list of links
- you need maintained, production-ready software - the list itself contains no code
- you need vendor-specific documentation for a particular SIEM or EDR

## Facets
- artifact type: learning-resource
- maturity: active
- function: security, monitoring, developer-tools
- domain: security, awesome-lists, developer-tools
- platform: cross-platform
- tags: awesome-list, threat-hunting, threat-detection, incident-response, curated-resources, mitre-attack, threat-simulation

## Member repositories
- 0x4D31/awesome-threat-detection (main) score 59

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:08:57.378253+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-29T18:19:09.187521+00:00, confidence not recorded.
  - readme: https://github.com/0x4D31/awesome-threat-detection (fetched 2026-08-28T04:08:57.378253+00:00, sha 31f2d11c27dc)
  - homepage: https://0x4d31.github.io/awesome-threat-detection/ (fetched 2026-08-29T09:03:14.304339+00:00, sha bb807f79948e)
- Data as of 2026-08-30T08:39:29.467469+00:00.
