ExabeamLabs / Content-Library-CIM1
☆14Updated 6 months ago
Alternatives and similar repositories for Content-Library-CIM1:
Users that are interested in Content-Library-CIM1 are comparing it to the libraries listed below
- Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help det…☆49Updated 7 months ago
- This repository hosts community contributed Kestrel huntflows (.hf) and huntbooks (.ipynb)☆32Updated last year
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆60Updated 9 months ago
- The Sigma command line interface based on pySigma☆142Updated last week
- ☆34Updated last month
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆73Updated last week
- Synthetic Adversarial Log Objects: A Framework for synthentic log generation☆77Updated last year
- A collection of tips for using MISP.☆74Updated last month
- ☆48Updated 2 years ago
- Dettectinator - The Python library to your DeTT&CT YAML files.☆107Updated 2 weeks ago
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆66Updated 2 weeks ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆50Updated 2 years ago
- Cleanup of older MISP events can require some work until now☆25Updated 2 years ago
- MISP-STIX-Converter - Python library to handle the conversion between MISP and STIX formats☆53Updated 3 weeks ago
- An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.☆51Updated 2 years ago
- ☆86Updated 5 months ago
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆52Updated 3 months ago
- Open Threat-Informed Detection Engineering☆32Updated 3 weeks ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆146Updated last year
- A tool that allows you to document and assess any security automation in your SOC☆45Updated 2 months ago
- Swagger/ OpenAPI specifications for security products and services☆75Updated last week
- Run Velociraptor on Security Onion☆37Updated 2 years ago
- An opensource sigma conversion tool built using pysigma☆113Updated last month
- An open source platform to support analysts to organise their case and tasks☆65Updated this week
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆137Updated last week
- Augmentation to Machine Readable CTI☆27Updated last month
- pySigma Splunk backend☆35Updated last week
- Run zeek with zeekctl in docker☆51Updated 4 months ago
- Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents☆38Updated 9 months ago
- Import CrowdStrike Threat Intelligence into your instance of MISP☆42Updated 3 months ago