CrowdStrike / MISP-tools
Import CrowdStrike Threat Intelligence into your instance of MISP
☆46Updated last month
Alternatives and similar repositories for MISP-tools:
Users that are interested in MISP-tools are comparing it to the libraries listed below
- Dettectinator - The Python library to your DeTT&CT YAML files.☆111Updated last month
- A collection of various SIEM rules relating to malware family groups.☆66Updated 10 months ago
- Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques☆132Updated last year
- This repository contains Splunk queries to hunt some anomalies☆42Updated 2 years ago
- An opensource sigma conversion tool built using pysigma☆125Updated 4 months ago
- User Feedback Space of #MitreAssistant☆37Updated last year
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆122Updated last year
- A collection of tips for using MISP.☆74Updated 4 months ago
- ☆58Updated last year
- Full of public notes and Utilities☆98Updated 2 months ago
- Collects a listing of MITRE ATT&CK Techniques, then discovers Splunk ESCU detections for each technique☆67Updated last year
- MISP to Sentinel integration☆67Updated last month
- A repository of my own Sigma detection rules.☆158Updated 8 months ago
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆77Updated 11 months ago
- ☆83Updated 2 months ago
- Convert Sigma rules to LogRhythm searches☆21Updated 3 years ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆63Updated last year
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆38Updated last month
- SentinelOne STAR Rules☆60Updated 2 months ago
- ☆72Updated 6 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆84Updated 3 months ago
- Rules generated from our investigations.☆194Updated last month
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆90Updated this week
- A tool that allows you to document and assess any security automation in your SOC☆46Updated 6 months ago
- Repository of public reference frameworks for the DFIR community.☆116Updated last year
- Developer enhancements (DX) for FalconPy, the CrowdStrike Python SDK☆38Updated last week
- A PowerShell incident response script for quick triage☆80Updated 2 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆70Updated last year
- MISP Playbooks☆199Updated 2 months ago
- Finding ClickFix and FakeCAPTCHA like it's 1999☆35Updated this week