CrowdStrike / FDR
Falcon Data Replicator
☆30Updated last month
Alternatives and similar repositories for FDR:
Users that are interested in FDR are comparing it to the libraries listed below
- Developer enhancements (DX) for FalconPy, the CrowdStrike Python SDK☆39Updated 3 weeks ago
- Collection of useful Canary tools☆75Updated last month
- Unleash the power of the Falcon Platform at the CLI☆113Updated last week
- ☆91Updated 2 years ago
- Tools to automate and/or expedite response.☆113Updated 6 months ago
- ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit l…☆153Updated last month
- BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.☆41Updated 2 years ago
- ☆33Updated 6 years ago
- Recon Hunt Queries☆76Updated 3 years ago
- ☆54Updated 3 years ago
- An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.☆51Updated 2 years ago
- Attack Range to test detection against nativel serverless cloud services and environments☆35Updated 3 years ago
- misp-cloud - Cloud-ready images of MISP☆72Updated 2 years ago
- A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.☆192Updated this week
- Synapse: a Meta Alert Feeder for TheHive, a Security Incident Response Platform☆71Updated last year
- Salt States for Configuring the SIFT Workstation☆97Updated this week
- A community event for security researchers to share their favorite notebooks☆107Updated 11 months ago
- CrowdStrike's Open Source Policy & Contribution Guide☆39Updated last year
- Cloud security tutorials and best practices☆38Updated last year
- Simple Docker-based quickstart for osquery, Fleet, and ELK stack☆62Updated last year
- Discover for Cloud and Containers Azure☆28Updated last month
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆104Updated last month
- A dataset containing Office 365 Unified Audit Logs for security research and detection☆48Updated 2 years ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆36Updated 2 years ago
- Security Monitoring Resolution Categories☆138Updated 3 years ago
- Public REPO for splunkbase app☆19Updated 3 years ago
- Tool to extract Sessions, MessageID(s) and find the emails belonging to MessageID(s). This script utilizes the MailItemsAccessed features…☆38Updated 4 years ago
- This repo represents work the Phantom Community collaborates on to build apps and learn.☆12Updated 3 years ago