0xbad53c / wazuh-detection-rules
Our collection of Wazuh detection rules for our Offense Lab
☆13Updated 3 years ago
Alternatives and similar repositories for wazuh-detection-rules:
Users that are interested in wazuh-detection-rules are comparing it to the libraries listed below
- Sysmon and wazuh integration with Sigma sysmon rules [updated]☆64Updated 3 years ago
- collector/runner☆65Updated last week
- ☆18Updated 3 years ago
- A Sigma to Wazuh / OSSEC converter including a generated Windows Sysmon ruleset☆33Updated 4 years ago
- ☆15Updated 2 years ago
- Collection of Suricata rule sets that I use modified to my environments.☆39Updated 4 years ago
- A repository of Sysmon For Linux configuration modules☆15Updated 3 years ago
- Wazuh integration TheHive☆34Updated 2 years ago
- ☆41Updated 2 years ago
- Look into EDR events from network☆23Updated 10 months ago
- Kerberoast Detection Script☆30Updated 4 months ago
- ☆41Updated 11 months ago
- Workflows for Shuffle☆21Updated 2 years ago
- Run Velociraptor on Security Onion☆37Updated 2 years ago
- PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Pac…☆95Updated 3 years ago
- BlueBox Malware analysis Box and Cyber threat intelligence.☆40Updated 2 years ago
- IOCPARSER.COM is a Fast and Reliable service that enables you to extract IOCs and intelligence from different data sources.☆34Updated 3 years ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆34Updated 2 years ago
- gundog - guided hunting in Microsoft Defender☆52Updated 3 years ago
- Repo for Automations and other solutions for Elastic SIEM/Security.☆18Updated 3 years ago
- A Ruleset to enhance detection capabilities of Ossec using Sysmon☆91Updated 2 years ago
- Notebooks created to attack and secure Active Directory environments☆27Updated 5 years ago
- Bloodhound Portable for Windows☆51Updated last year
- ☆17Updated 3 years ago
- Create alerts in The Hive from your Graylog alerts, to be turned into Hive cases.☆44Updated 4 years ago
- PowerShell scripts for fast Windows Event Collector configuration with Palantir toolset☆22Updated 2 years ago
- A tool to assess the compliance of a VMware vSphere environment against the CIS Benchmark.☆49Updated 2 years ago
- Indicator of Compromise Scanner for CVE-2019-19781☆94Updated 4 years ago
- List of PowerShell commands and commandlets that should be in your Powershel watchlist☆37Updated 3 years ago
- Defence Against the Dark Arts☆34Updated 5 years ago