GACWR / OpenUBA
A robust, and flexible open source User & Entity Behavior Analytics (UEBA) framework used for Security Analytics. Developed with luv by Data Scientists & Security Analysts from the Cyber Security Industry. [PRE-ALPHA]
☆427Updated last year
Alternatives and similar repositories for OpenUBA
Users that are interested in OpenUBA are comparing it to the libraries listed below
Sorting:
- This content is analysis and research of the data sources currently listed in ATT&CK.☆409Updated last year
- Cyber Analytics Repository☆937Updated this week
- A curated Cyber "Security Orchestration, Automation and Response (SOAR)" awesome list.☆866Updated 8 months ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆791Updated 2 years ago
- Actionable analytics designed to combat threats☆984Updated 2 years ago
- User and Entity Behavior Analytics by deep learning☆110Updated 4 years ago
- A repository of curated datasets from various attacks☆648Updated this week
- Open Source Security Events Metadata (OSSEM)☆1,266Updated 2 years ago
- A set of Zeek scripts to detect ATT&CK techniques.☆589Updated 10 months ago
- Python Script to access ATT&CK content available in STIX via a public TAXII server☆565Updated 4 months ago
- Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark☆435Updated last year
- Security event correlation engine for ELK stack☆440Updated 10 months ago
- A curated list of the most important and useful resources about Threat Detection,Hunting and Intelligence.☆558Updated 2 years ago
- Threat Report ATT&CK™ Mapping (TRAM) is a tool to aid analyst in mapping finished reports to ATT&CK.☆350Updated 3 years ago
- Extract and aggregate threat intelligence.☆863Updated last year
- Phantom Community Playbooks☆500Updated 3 months ago
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,156Updated last year
- PCAP Samples for Different Post Exploitation Techniques☆357Updated 4 years ago
- ☆125Updated last year
- SIEM Tactics, Techiques, and Procedures☆627Updated last week
- A Python package to interact with the Mitre ATT&CK Framework☆477Updated last year
- Attack Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by devel…☆607Updated last week
- Open Source SIEM (Security Information and Event Management system).☆210Updated last year
- STIX data representing MITRE ATT&CK☆401Updated last week
- Suricata, Snort and Zeek IDS rule and pcap testing system☆477Updated 4 months ago
- Python library using the MISP Rest API☆462Updated this week
- CASCADE Server☆269Updated 2 years ago
- Re-play Security Events☆1,641Updated last year
- Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.☆312Updated 7 months ago
- MISP trainings, threat intel and information sharing training materials with source code☆407Updated last week