CrowdStrike / gofalcon
Golang-based SDK to CrowdStrike's APIs
☆66Updated last week
Alternatives and similar repositories for gofalcon:
Users that are interested in gofalcon are comparing it to the libraries listed below
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆108Updated 7 months ago
- pocket guide for core detection engineering concepts☆28Updated 2 years ago
- Unleash the power of the Falcon Platform at the CLI☆117Updated this week
- Developer enhancements (DX) for FalconPy, the CrowdStrike Python SDK☆38Updated last week
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆63Updated 2 years ago
- A Go implementation and parser for Sigma rules.☆88Updated 8 months ago
- A Golang library for interacting with the EPSS (Exploit Prediction Scoring System).☆28Updated 2 months ago
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 4 years ago
- ☆43Updated last month
- ☆58Updated 2 years ago
- ☆16Updated 3 weeks ago
- Automated testing, generation & manipulation of #osquery packs☆72Updated 6 months ago
- A python script to acquire multiple aws ec2 instances in a forensically sound-ish way☆38Updated 3 years ago
- Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indi…☆103Updated 6 months ago
- MDE relies on some of the Audit settings to be enabled☆97Updated 2 years ago
- Adversary emulation for EDR/SIEM testing (macOS/Linux)☆41Updated last year
- When good OAuth apps go rogue. Documents observed OAuth application tradecraft☆75Updated last month
- A POC to implement Detection-as-Code with Terraform and Sumo Logic.☆27Updated last year
- The Event Maturity Matrix (EMM) is a comprehensive framework that provides clarity regarding the capabilities and nuances of SaaS audit l…☆21Updated 8 months ago
- A tool that allows you to document and assess any security automation in your SOC☆46Updated 6 months ago
- Cisco Orbital - Osquery queries by Talos☆132Updated 8 months ago
- Cloud Analytics helps defenders detect attacks to their cloud infrastructure by developing behavioral analytics for cloud platforms as we…☆53Updated 2 years ago
- defendA Data Lake. A firehose pipeline to athena providing enrichment and normalization for security events☆16Updated 2 years ago
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆73Updated last year
- Adversarial Interception Mission Oriented Discovery and Disruption Framework, or AIMOD2, is a structured threat hunting approach to proac…☆88Updated last year
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆20Updated 7 months ago
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆29Updated last year
- Repository for Cortex XDR and Cortex XSIAM XQL queries and more!☆27Updated 11 months ago
- Security Alert Decoration☆27Updated 2 weeks ago
- ☆65Updated 11 months ago