EFForg / yaya
Yet Another Yara Automaton - Automatically curate open source yara rules and run scans
☆271Updated last year
Alternatives and similar repositories for yaya:
Users that are interested in yaya are comparing it to the libraries listed below
- User guide of MISP☆263Updated 2 weeks ago
- Chain Reactor is an open source framework for composing executables that simulate adversary behaviors and techniques on Linux endpoints.☆298Updated 2 months ago
- A set of Zeek scripts to detect ATT&CK techniques.☆571Updated 6 months ago
- Collecting & Hunting for IOCs with gusto and style☆236Updated 3 years ago
- A collection of YARA rules we wish to share with the world, most probably referenced from http://blog.inquest.net.☆369Updated 2 years ago
- simple YARA-based IOC scanner☆165Updated last week
- MISP trainings, threat intel and information sharing training materials with source code☆393Updated last month
- MISP Docker (XME edition)☆283Updated last year
- ☆170Updated 6 months ago
- 🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.☆261Updated last year
- ☆211Updated last year
- DFIRTrack - The Incident Response Tracking Application☆487Updated 4 months ago
- A live dashboard for a real-time overview of threat intelligence from MISP instances☆195Updated last year
- This is a repository for freq.py and freq_server.py☆203Updated 4 years ago
- IOC from articles, tweets for archives☆312Updated last year
- Threat Hunting & Incident Investigation with Osquery☆204Updated 2 years ago
- Simple Bash IOC Scanner☆713Updated 2 years ago
- A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework☆350Updated 4 years ago
- Detecting ATT&CK techniques & tactics for Linux☆258Updated 4 years ago
- A framework for orchestrating forensic collection, processing and data export☆303Updated this week
- Modules for expansion services, enrichment, import and export in MISP and other tools.☆351Updated 3 weeks ago
- Automated Use Case Testing☆165Updated 6 years ago
- Zeek-Formatted Threat Intelligence Feeds☆347Updated this week
- Distributed malware processing framework based on Python, Redis and S3.☆397Updated 2 months ago
- Repository of YARA rules made by Trellix ATR Team☆574Updated last year
- A list of my personal projects☆173Updated 2 years ago
- Set of Yara rules for finding files using magics headers☆134Updated 4 years ago
- Yara Rule Analyzer and Statistics☆364Updated last year
- Threat Hunting tool about Sysmon and graphs☆329Updated last year