ChiefGyk3D / pfsense-siem-stackLinks
Comprehensive pfSense deployment, monitoring, and security knowledge base: From basic configuration to advanced SIEM infrastructure, IDS/IPS optimization, and network security automation.
☆20Updated last week
Alternatives and similar repositories for pfsense-siem-stack
Users that are interested in pfsense-siem-stack are comparing it to the libraries listed below
Sorting:
- Fast IOC and YARA Scanner☆88Updated 5 years ago
- Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents☆51Updated last year
- DShield Sensor Log Collection with ELK☆44Updated last week
- A PowerShell-based script to analyze network logs from CSV files and detect potential beaconing behavior. Supports VirusTotal integration…☆17Updated 8 months ago
- Research repository tracking affected IPs from the Fortigate CVE-2022-40684 configuration leak by Belsen Group☆86Updated last year
- Playbook-NG is a stateless web-based application used to match incident findings with countermeasures for adversary containment and evict…☆156Updated 2 months ago
- A security analysis tool that identifies DNS queries made by browser extensions, empowering security teams to detect and investigate susp…☆185Updated 11 months ago
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆53Updated last year
- Scripts for importing threat feeds and CTI articles, blogs, and reports into MISP.☆18Updated 7 months ago
- Collection of useful Canary tools☆93Updated last week
- ☆105Updated last month
- Repo for experimenting and testing MCP server builds for CTI-related research.☆27Updated 8 months ago
- Elastic version of SOC prime watcher rules☆30Updated last year
- Sigma detection rules for hunting with the threathunting-keywords project☆58Updated 11 months ago
- ASR Configurator, Essentials and Atomic Testing☆101Updated 9 months ago
- An index of publicly available and open-source threat detection rulesets.☆131Updated 9 months ago
- Leveraging MISP indicators via a pDNS-based infrastructure as a poor man’s SOC.☆56Updated 3 months ago
- A tool that allows you to document and assess any security automation in your SOC☆48Updated last year
- AIL project training materials☆39Updated 6 months ago
- Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indi…☆110Updated last year
- Conference presentations☆60Updated 3 months ago
- Extracting IoC data from eMail☆140Updated last month
- A repository to help CTI teams tackle the challenges around collection and research by providing guidance from experienced practitioners☆115Updated last year
- Domain Response is a tool that is designed to help you automate the investigation for a domain. This tool is specificly designed to autom…☆49Updated last month
- ☆78Updated 3 weeks ago
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆17Updated 2 years ago
- Turn any blog into structured threat intelligence.☆51Updated last week
- A preconfigured Velociraptor triage collector☆73Updated 3 weeks ago
- ☆22Updated 3 years ago
- MCP to help Defenders Detection Engineer Harder and Smarter☆199Updated last week