ANSSI-FR / AnoMark
Algorithme d'apprentissage statistique permettant de créer un modèle sur les lignes de commandes des évènements "Création de Processus", afin de détecter des anomalies dans les évènements futurs
☆83Updated last year
Alternatives and similar repositories for AnoMark:
Users that are interested in AnoMark are comparing it to the libraries listed below
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆32Updated 3 months ago
- The core backend server handling API requests and task management☆38Updated last week
- Powershell module for VMWare vSphere forensics☆150Updated 4 months ago
- A really good DFIR automation for collecting and analyzing evidence designed for cybersecurity professionals.☆153Updated 10 months ago
- Guide journalisation Microsoft☆60Updated 8 months ago
- Forensic Artifact Collection Tool Matrix☆83Updated 4 months ago
- A repository to help CTI teams tackle the challenges around collection and research by providing guidance from experienced practitioners☆83Updated 4 months ago
- ☆87Updated last month
- The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders und…☆118Updated 11 months ago
- Cyber Underground General Intelligence Requirements☆91Updated last year
- LotL RMM☆151Updated this week
- A repository to share publicly available Velociraptor detection content☆137Updated last week
- A tool collection for filtering and visualizing logon events. Designed to help answering the "Cotton Eye Joe" question (Where did you com…☆167Updated last month
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆118Updated last year
- Website for ail-typo-squatting library☆57Updated 9 months ago
- The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the hos…☆30Updated 3 years ago
- An opensource sigma conversion tool built using pysigma☆121Updated 3 months ago
- A zero dependency and customizable Python library for scanning Windows and Linux process memory.☆66Updated last year
- Automated YARA Rule Standardization and Quality Assurance Tool☆200Updated this week
- Open Source Platform for storing, organizing, and searching documents related to cyber threats☆163Updated last year
- Web Application for domain name monitoring / alerting☆63Updated 7 months ago
- MISP Playbooks☆188Updated last month
- Segugio allows the execution and tracking of critical steps in the malware detonation process, from clicking on the first stage to extrac…☆147Updated 6 months ago
- ☆127Updated 3 weeks ago
- DFIR ORC PARSER PROJECT☆25Updated 3 weeks ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆84Updated last month
- ☆67Updated 3 months ago
- Harness the power of Splunk for your investigations☆92Updated last week