ExabeamLabs / Content-Library-CIM2
☆17Updated last month
Alternatives and similar repositories for Content-Library-CIM2:
Users that are interested in Content-Library-CIM2 are comparing it to the libraries listed below
- Parse wazuh[HIDS] alerts into ECS mapping using Filebeat☆27Updated 4 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 months ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆146Updated last year
- Threat Detection & Anomaly Detection rules for popular open-source components☆50Updated 2 years ago
- Wazuh - Splunk App☆51Updated 4 months ago
- Security Analytics enables users for detecting security threats on their security event log data. It will also allow them to modify/tailo…☆74Updated this week
- Swagger/ OpenAPI specifications for security products and services☆75Updated last week
- Converts Netwitness log parser configuration to Logstash configuration☆20Updated 4 years ago
- ☆123Updated last year
- Threat Intelligence with Elastic - Minemeld integration with Elasticsearch☆19Updated 3 years ago
- Convert Sigma rules to LogRhythm searches☆19Updated 2 years ago
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆52Updated 3 months ago
- OSSEM Common Data Model☆55Updated 2 years ago
- Workflows for Shuffle☆21Updated 2 years ago
- Synapse: a Meta Alert Feeder for TheHive, a Security Incident Response Platform☆71Updated last year
- Web based S1 query navigator for one-click threat hunting☆18Updated 4 years ago
- Zeek Training Materials/Products☆37Updated this week
- This program exports MITRE ATT&CK framework in ELK dashboard☆78Updated 2 years ago
- OASIS TC Open Repository: TAXII 2 Client Library Written in Python☆113Updated 9 months ago
- A Ruleset to enhance detection capabilities of Ossec using Sysmon☆87Updated 2 years ago
- ☆48Updated last week
- SIEM Logstash parsing for more than hundred technologies☆182Updated this week
- Actionable analytics designed to combat threats based on MITRE's ATT&CK.☆22Updated 5 years ago
- This is a repository of vendor-agnostic workflows provided for those interested in deploying Security Orchestration, Automation, and Resp…☆78Updated 3 years ago
- OSSEM Data Dictionaries☆59Updated last week
- Phantom Apps Repo☆82Updated 3 years ago
- A curated list of awesome things related to TheHive & Cortex☆174Updated 3 years ago
- Zeek support for Community ID flow hashing.☆35Updated last year
- A Sigma to Wazuh / OSSEC converter including a generated Windows Sysmon ruleset☆33Updated 4 years ago
- This repository contains a few examples of actions that can be added to rules within Elastic Security.☆22Updated 2 years ago