BatteryCandy / osquery-splunk-dashboards
Collection of operational focused osquery dashboards.
☆11Updated 4 years ago
Alternatives and similar repositories for osquery-splunk-dashboards:
Users that are interested in osquery-splunk-dashboards are comparing it to the libraries listed below
- Recon Hunt Queries☆76Updated 3 years ago
- Automated testing, generation & manipulation of #osquery packs☆72Updated 3 months ago
- ☆34Updated last year
- ☆33Updated 6 years ago
- ☆65Updated 8 months ago
- A tool to run and validate telemetry for Atomic Red Team tests☆14Updated 10 months ago
- Provides an easy way to collect and send Slack access & integration logs.☆13Updated 3 years ago
- A packer utility to create and capture DFIR Image for use AWS & Azure☆14Updated 5 years ago
- Osquery Mangement Server☆114Updated 4 years ago
- ☆18Updated 3 years ago
- Golang command line tool for the macOS Endpoint Security Framework☆29Updated 5 years ago
- https://registry.terraform.io/providers/CrowdStrike/crowdstrike/latest/docs☆12Updated last week
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆27Updated last year
- Attack Tool Timing and Reporting - Structured Attack Logging Format☆21Updated 2 years ago
- Run Sigma detection rules on logs from the new MacOS EndpointSecurity Framework☆20Updated 4 years ago
- ☆39Updated 2 weeks ago
- Deploy Kolide's Fleet into AWS using Terraform.☆15Updated 6 years ago
- Simple Docker-based quickstart for osquery, Fleet, and ELK stack☆62Updated last year
- The Event Maturity Matrix (EMM) is a comprehensive framework that provides clarity regarding the capabilities and nuances of SaaS audit l…☆18Updated 5 months ago
- Things to know when DFIR occurs near a vault deployment.☆43Updated 6 years ago
- GCP CSPM using Google Sheets☆34Updated 7 months ago
- Public release of Whalehoney Honeypot☆29Updated 2 years ago
- pocket guide for core detection engineering concepts☆27Updated last year
- Security Alert Decoration☆26Updated this week
- Osquery Packs we use for customer security hardening☆12Updated 3 months ago
- pollen - A command-line tool for interacting with TheHive☆35Updated 5 years ago
- Remotely collect linux live forensics artifacts.☆13Updated 2 years ago
- defendA Data Lake. A firehose pipeline to athena providing enrichment and normalization for security events☆16Updated last year
- Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)☆51Updated 2 years ago
- Collect chrome extensions from various devices and find out if they are malicious☆22Updated 2 months ago