ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.
-
Updated
Apr 3, 2026 - Python
ATHF is a framework for agentic threat hunting - building systems that can remember, learn, and act with increasing autonomy.
An ongoing & curated collection of awesome software best practices and remediation techniques, libraries and frameworks, E-books and videos, Technical guidelines and important resources about Threat Intelligence.
An ongoing & curated collection of awesome software best practices and remediation techniques, libraries and frameworks, E-books and videos, Technical guidelines and important resources about Threat Detection & Hunting.
Collection of Suricata rule sets that I use modified to my environments.
Threat Feeds, Threat lists, and regular lists of known IP ranges and domains. It updates every 4 hours.
Threat Response Serverless Relay Template
Threat Response CTIM Bundle Builder
FortiGate API (for FortiOS API v2) library wrapper. Active support for core Firewall & System plus DNS Filtering & External ThreatFeed Connector's.
Threat Response Relay Module CLI
Example scripts for authenticating to the Threat Response APIs
How to install Have I been pwned for Cisco's SecureX walk through using Ubuntu 20.04 as the desktop environment
Generates a threat feed IP list from a user-furnished ASN list.
Example implemention for using OAuth2 Authorization Code Grant Credentials
Threat Response Serverless Relay for Auth0 Signals
Add a description, image, and links to the threat-response topic page so that developers can more easily learn about it.
To associate your repository with the threat-response topic, visit your repo's landing page and select "manage topics."