ANSSI-FR / AnoMark
Algorithme d'apprentissage statistique permettant de créer un modèle sur les lignes de commandes des évènements "Création de Processus", afin de détecter des anomalies dans les évènements futurs
☆78Updated 8 months ago
Related projects ⓘ
Alternatives and complementary repositories for AnoMark
- ☆82Updated 2 months ago
- Xavier Framework is a user interface wrapper built on top of the Volatility(c) memory forensics framework.☆45Updated 2 years ago
- Forensic Artifact Collection Tool Matrix☆73Updated 2 years ago
- The core backend server handling API requests and task management☆31Updated this week
- MISP Playbooks☆174Updated 3 weeks ago
- Automated YARA Rule Standardization and Quality Assurance Tool☆159Updated last week
- LotL RMM☆85Updated 3 weeks ago
- Guide journalisation Microsoft☆57Updated 3 months ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆66Updated this week
- A pySigma wrapper to manage detection rules.☆27Updated this week
- Rules shared by the community from 100 Days of YARA 2024☆77Updated 6 months ago
- ☆56Updated last week
- A Jupyter notebook to assist with the analysis of the output generated from Volatility memory extraction framework.☆94Updated last year
- Harness the power of Splunk for your investigations☆76Updated last week
- Powershell module for VMWare vSphere forensics☆140Updated this week
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆138Updated last month
- The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the hos…☆29Updated 2 years ago
- Rules Shared by the Community from 100 Days of YARA 2023☆77Updated last year
- A toolkit for the post-mortem examination of Docker containers from forensic HDD copies☆94Updated 8 months ago
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆50Updated 2 weeks ago
- A collection of tips for using MISP.☆74Updated 7 months ago
- The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders und…☆110Updated 7 months ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆25Updated 3 weeks ago
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆129Updated this week
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆116Updated 11 months ago
- A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.☆148Updated 5 months ago
- Collection of scripts provided for public use☆31Updated 3 weeks ago
- The Threat Actor Profile Guide for CTI Analysts☆96Updated last year
- An open source platform to support analysts to organise their case and tasks☆55Updated last week
- A repository to share publicly available Velociraptor detection content☆119Updated this week