ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.
-
Updated
Sep 11, 2026 - Python
ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.
An ongoing & curated collection of awesome software best practices and remediation techniques, libraries and frameworks, E-books and videos, Technical guidelines and important resources about Threat Intelligence.
An ongoing & curated collection of awesome software best practices and remediation techniques, libraries and frameworks, E-books and videos, Technical guidelines and important resources about Threat Detection & Hunting.
Collection of Suricata rule sets that I use modified to my environments.
Threat Feeds, Threat lists, and regular lists of known IP ranges and domains. It updates every 4 hours.
FortiGate API (for FortiOS API v2) library wrapper. Active support for core Firewall & System plus DNS Filtering & External ThreatFeed Connector's.
Example scripts for authenticating to the Threat Response APIs
Generates a threat feed IP list from a user-furnished ASN list.
How to install Have I been pwned for Cisco's SecureX walk through using Ubuntu 20.04 as the desktop environment
Standardized incident response procedures, playbooks, and runbooks for SOC teams protecting critical infrastructure
Network Intrusion Detection System (NIDS) is a machine-learning-based system for detecting malicious network traffic in real time. The system uses the CIC-IDS2017 dataset to train supervised learning models and combines packet capture, flow generation, feature extraction, ML-based classification, alerting, and automated IP blocking into a single pi
A Linux daemon that watches your server and bites back - real-time surveillance and automated threat response, in C.
Velociraptor-inspired DFIR and endpoint investigation lab using MITRE ATT&CK techniques.
Governance-first safety architecture with continuous loop verification and adaptive threat response.
Collects live Windows artifacts, evaluates them against built-in detection rules, and tells you whether the host is compromised. One script, no dependencies.
Automated incident response playbooks for security operations
To associate your repository with the threat-response topic, visit your repo's landing page and select "manage topics."