CiscoCXSecurity / log4jLinks
Detection rules to look for Log4J usage and exploitation
☆18Updated 4 months ago
Alternatives and similar repositories for log4j
Users that are interested in log4j are comparing it to the libraries listed below
Sorting:
- Simple Docker-based quickstart for osquery, Fleet, and ELK stack☆63Updated 2 years ago
- Unleash the power of the Falcon Platform at the CLI☆132Updated last month
- ☆34Updated 2 years ago
- Recon Hunt Queries☆79Updated 4 years ago
- Falcon Data Replicator☆35Updated last week
- Post-Infection Collection Toolkit☆95Updated 2 years ago
- Scripts from my book OS X Incident Response Scripting and Analysis -> https://www.amazon.com/dp/012804456X/ref=cm_sw_r_tw_dp_U_x_fQeLAb68…☆50Updated 9 years ago
- Actionable analytics designed to combat threats based on MITRE's ATT&CK.☆23Updated 6 years ago
- Tools related to work with Attack Flow (https://github.com/center-for-threat-informed-defense/attack-flow)☆44Updated 3 years ago
- ansible role to setup MISP, Malware Information Sharing Platform & Threat Sharing☆54Updated this week
- Synthetic Adversarial Log Objects: A Framework for synthentic log generation☆85Updated last year
- Python API for the LimaCharlie.io service.☆22Updated last week
- Run individual configuration, compliance and security controls or full compliance benchmarks for CIS for Zoom using Powerpipe and Steampi…☆66Updated 3 months ago
- OpenIOC rules to facilitate hunting for indicators of compromise☆37Updated 3 years ago
- Public release of Whalehoney Honeypot☆29Updated 3 years ago
- ☆18Updated 4 years ago
- ☆36Updated 5 months ago
- Cisco Orbital - Osquery queries by Talos☆135Updated last year
- A Splunk Technology Add-on to forward filtered ETW events.☆30Updated 5 years ago
- WebUI of MineMeld☆43Updated 2 years ago
- A tool to modify timestamps in a packet capture to a user selected date☆31Updated 4 years ago
- Elastic Beat for fetching and shipping Office 365 audit events☆68Updated 5 years ago
- ☆51Updated last month
- CrowdStrike Falcon log forwarder from falcon S3 bucket to your S3 bucket☆11Updated 4 years ago
- A collection of tips for using MISP.☆74Updated 11 months ago
- A python script to acquire multiple aws ec2 instances in a forensically sound-ish way☆38Updated 4 years ago
- A STIX 2.1 Extension Definition for the Course of Action (COA) object type. The nested property extension allows a COA to share machine-r…☆23Updated last year
- Import specific data sources into the Sigma generic and open signature format.☆78Updated 3 years ago
- [ARCHIVED -- USE TXT2DETECTION] A command line tool that converts Sigma Rules into STIX 2.1 Objects.☆12Updated 10 months ago
- ☆77Updated last week