GACWR / OpenUBA
A robust, and flexible open source User & Entity Behavior Analytics (UEBA) framework used for Security Analytics. Developed with luv by Data Scientists & Security Analysts from the Cyber Security Industry. [PRE-ALPHA]
☆393Updated 6 months ago
Related projects ⓘ
Alternatives and complementary repositories for OpenUBA
- A curated Cyber "Security Orchestration, Automation and Response (SOAR)" awesome list.☆807Updated 2 months ago
- Documentation of TheHive☆392Updated last year
- Actionable analytics designed to combat threats☆972Updated 2 years ago
- A set of Zeek scripts to detect ATT&CK techniques.☆563Updated 4 months ago
- Cyber Analytics Repository☆907Updated 7 months ago
- Python Script to access ATT&CK content available in STIX via a public TAXII server☆556Updated 5 months ago
- Open Source Security Events Metadata (OSSEM)☆1,238Updated last year
- Extract and aggregate threat intelligence.☆830Updated 9 months ago
- A repository of curated datasets from various attacks☆587Updated last week
- Documentation of Cortex☆170Updated last year
- This content is analysis and research of the data sources currently listed in ATT&CK.☆405Updated last year
- Security event correlation engine for ELK stack☆434Updated 4 months ago
- Open Source SIEM (Security Information and Event Management system).☆198Updated last year
- Phantom Community Playbooks☆472Updated 3 weeks ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆776Updated last year
- Threat Report ATT&CK™ Mapping (TRAM) is a tool to aid analyst in mapping finished reports to ATT&CK.☆346Updated 3 years ago
- TRAM is an open-source platform designed to advance research into automating the mapping of cyber threat intelligence reports to MITRE AT…☆450Updated 5 months ago
- Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark☆423Updated 9 months ago
- ☆125Updated 11 months ago
- Cortex Analyzers Repository☆433Updated this week
- Suricata and Snort IDS rule and pcap testing system☆449Updated this week
- MISP Docker (XME edition)☆283Updated 11 months ago
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,137Updated last year
- STIX data representing MITRE ATT&CK☆342Updated 2 weeks ago
- SIEM Tactics, Techiques, and Procedures☆585Updated 3 weeks ago
- Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.☆300Updated last month
- A knowledge base of actionable Incident Response techniques☆612Updated 2 years ago
- A python app to predict Att&ck tactics and techniques from cyber threat reports☆115Updated 11 months ago
- Defanged Indicator of Compromise (IOC) Extractor.☆505Updated 2 months ago
- A collection of red team and adversary emulation resources developed and released by MITRE.☆491Updated 3 years ago