CiscoCXSecurity / log4jLinks
Detection rules to look for Log4J usage and exploitation
☆18Updated 2 months ago
Alternatives and similar repositories for log4j
Users that are interested in log4j are comparing it to the libraries listed below
Sorting:
- Simple Docker-based quickstart for osquery, Fleet, and ELK stack☆63Updated 2 years ago
- Post-Infection Collection Toolkit☆95Updated 2 years ago
- Unleash the power of the Falcon Platform at the CLI☆123Updated last week
- Scripts from my book OS X Incident Response Scripting and Analysis -> https://www.amazon.com/dp/012804456X/ref=cm_sw_r_tw_dp_U_x_fQeLAb68…☆50Updated 8 years ago
- ☆34Updated 2 years ago
- Recon Hunt Queries☆78Updated 4 years ago
- VMware Carbon Black Cloud Python SDK☆44Updated 2 months ago
- Import specific data sources into the Sigma generic and open signature format.☆78Updated 3 years ago
- A tool to modify timestamps in a packet capture to a user selected date☆31Updated 4 years ago
- ☆67Updated last week
- Falcon Data Replicator☆33Updated 5 months ago
- Tools related to work with Attack Flow (https://github.com/center-for-threat-informed-defense/attack-flow)☆44Updated 3 years ago
- Cisco Orbital - Osquery queries by Talos☆134Updated last year
- Run individual configuration, compliance and security controls or full compliance benchmarks for CIS for Zoom using Powerpipe and Steampi…☆66Updated last month
- OpenIOC rules to facilitate hunting for indicators of compromise☆37Updated 3 years ago
- Collection of useful Canary tools☆88Updated last month
- ☆36Updated 4 years ago
- ☆18Updated 4 years ago
- fqdn_parser (Fully Qualified Domain Name Parser) is a library for parsing FQDNs into their component parts, as well as providing addition…☆27Updated last year
- ☆119Updated last year
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆37Updated 3 years ago
- Public release of Whalehoney Honeypot☆29Updated 3 years ago
- Creating an ATT&CK Navigator layer with the detection coverage of the signals available within Tanium Threat Response.☆11Updated 4 years ago
- Tools and scripts by Arctic Wolf☆69Updated 2 months ago
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆79Updated 3 months ago
- Synthetic Adversarial Log Objects: A Framework for synthentic log generation☆84Updated last year
- pocket guide for core detection engineering concepts☆30Updated 2 years ago
- pCraft is a PCAP Crafter, which creates a PCAP from an AMI scenario.☆90Updated last year
- macOS .DS_Store Parser☆70Updated 4 years ago
- Dashboards for conducting forensic investigation using windows events in Kibana☆18Updated 6 years ago