23 curated GitHub awesome-lists I cross-reference when building DFIR / CTI tradecraft. Each card opens the canonical README; the why line under each entry explains the niche it fills better than its peers.
Awesome-list READMEs decay; star count + the maintainer's commit cadence are freshness proxies, not guarantees. Verify a specific link before relying on it.
Spanish/English dashboard tracking ransomware incidents with country / sector / timeline charts. Open-directory at /rescate/ + /screenshots/ provides 180+ ransom-note transcripts and leak-site landing-page captures. No RSS feed.
why: The only public source I have found that ships per-group ransom-note transcripts AND leak-site screenshots together - linked from the External Sources block on /threatintel.
Model Context Protocol servers that expose OSINT tools (Maigret, Holehe, etc.) to LLM agents. Useful for wiring OSINT capabilities into Claude / Cursor / Cline.
why: Bridges OSINT tradecraft and the agent stack - the place to discover OSINT MCPs you can wire into your IDE.
The de-facto CTI reference list - sources, formats (STIX/TAXII), frameworks (MITRE, Diamond), training, books, and research blogs. Updated for over a decade.
why: Best single index of CTI primary sources. Cross-reference whenever a vendor claims novelty.
Smaller, recently-curated CTI list - feeds, platforms, and tools focused on detect / analyze / respond. Lighter than hslatman but easier to skim end-to-end.
why: Useful as a quick-glance complement to hslatman - different curator, slightly different selection bias.
Mirrored KQL detection-rule library - Defender XDR / Microsoft Sentinel rules with a focus on AI-related, identity-attack, and emerging-threat detections. Active commit cadence.
why: Sharper / niche complement to Azure-Sentinel - wired into /threatintel/rules as a detection-rule source so latest commits appear in the live feed.
Meta-list of awesome-lists - pen-test, exploit dev, web security, mobile, hardware, malware, CTF, OSINT, social engineering. The "start here" index for everything else.
why: The directory of directories. When a sub-domain is too niche for the lists in this catalogue, find its sibling here.
The security tester's companion - usernames, passwords, fuzzing payloads, web-content discovery wordlists, data patterns. Not strictly an awesome-list, but the most-referenced security wordlist collection in existence.
why: Half of the security-testing tools in this catalogue have SecLists as a default wordlist dependency.
Curated list of legal hacking environments to practise on - CTF platforms, intentionally-vulnerable apps, lab simulators, war games. Skill-building only, no live targets.
why: When upskilling on a new technique, this is faster than building a lab from scratch.
Tools for PCAP capture, analysis, and protocol dissection - from Wireshark plugins to ML-driven anomaly detectors. Includes sample-PCAP corpora for testing.
why: IR-focused complement to meirwah/awesome-incident-response - sharper on the network-forensics niche.