ANSSI-FR / AnoMark
Algorithme d'apprentissage statistique permettant de créer un modèle sur les lignes de commandes des évènements "Création de Processus", afin de détecter des anomalies dans les évènements futurs
☆81Updated last year
Alternatives and similar repositories for AnoMark:
Users that are interested in AnoMark are comparing it to the libraries listed below
- ☆84Updated last week
- Forensic Artifact Collection Tool Matrix☆82Updated 3 months ago
- The core backend server handling API requests and task management☆35Updated last week
- Rules Shared by the Community from 100 Days of YARA 2023☆77Updated last year
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆116Updated last year
- Xavier Framework is a user interface wrapper built on top of the Volatility(c) memory forensics framework.☆45Updated 2 years ago
- Open Source Platform for storing, organizing, and searching documents related to cyber threats☆162Updated last year
- ☆66Updated 2 months ago
- Guide journalisation Microsoft☆60Updated 7 months ago
- DFIR ORC PARSER PROJECT☆25Updated last month
- A toolkit for the post-mortem examination of Docker containers from forensic HDD copies☆97Updated last year
- A collection of tips for using MISP.☆74Updated 2 months ago
- A repository to help CTI teams tackle the challenges around collection and research by providing guidance from experienced practitioners☆75Updated 3 months ago
- An open source platform to support analysts to organise their case and tasks☆66Updated last week
- The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the hos…☆30Updated 2 years ago
- Automated YARA Rule Standardization and Quality Assurance Tool☆192Updated this week
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆32Updated 2 months ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆74Updated this week
- The Threat Actor Profile Guide for CTI Analysts☆104Updated last year
- BlackBerry Threat Research & Intelligence☆97Updated last year
- MISP Playbooks☆184Updated last week
- ☆5Updated 3 months ago
- A repository to share publicly available Velociraptor detection content☆126Updated this week
- Rules shared by the community from 100 Days of YARA 2024☆83Updated last month
- JPCERT/CC public YARA rules repository☆106Updated 2 months ago
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆106Updated last year
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆51Updated 3 months ago
- Adversarial Interception Mission Oriented Discovery and Disruption Framework, or AIMOD2, is a structured threat hunting approach to proac…☆86Updated last year
- Cyber Underground General Intelligence Requirements☆90Updated last year
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆109Updated 3 months ago