HASecuritySolutions / Logstash
Contains Logstash related content including tons of Logstash configurations
☆253Updated 3 years ago
Alternatives and similar repositories for Logstash:
Users that are interested in Logstash are comparing it to the libraries listed below
- ☆131Updated last year
- Splunk code (SPL) for serious threat hunters and detection engineers.☆273Updated last year
- Mark Baggett's (@MarkBaggett - GSE #15, SANS SEC573 Author) tool for detecting randomness using NLP techniques rather than pure entropy c…☆125Updated 2 years ago
- Documentation of TheHive☆396Updated last year
- ☆213Updated last year
- Documentation of Cortex☆174Updated last year
- Automated Use Case Testing☆167Updated 6 years ago
- Main MineMeld documentation repo☆378Updated 7 years ago
- Python API Client for TheHive☆220Updated 2 weeks ago
- Engine of MineMeld☆141Updated 2 years ago
- ☆118Updated 3 years ago
- Automated deployment scripts for the RockNSM network hunting distribution.☆450Updated last year
- SIGMA UI is a free open-source application based on the Elastic stack and Sigma Converter (sigmac)☆185Updated 3 years ago
- Carbon Black API - Python language bindings☆145Updated 6 months ago
- MISP Docker (XME edition)☆283Updated last year
- Hackish nonsense to interact with the MITRE ATT&CK API via Python☆16Updated 4 years ago
- CASCADE Server☆266Updated 2 years ago
- Graylog Processing Pipeline functions to enrich log messages with IoC information from threat intelligence databases☆153Updated last year
- Threat Feed Aggregation, Made Easy☆167Updated 4 years ago
- A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆68Updated 7 years ago
- A Splunk app to use MISP in background☆110Updated last week
- SIEM Logstash parsing for more than hundred technologies☆183Updated last month
- Security Monitoring Resolution Categories☆138Updated 3 years ago
- Windows Event Forwarding subscriptions, configuration files and scripts that assist with implementing ACSC's protect publication, Technic…☆216Updated last month
- The Phishing Intelligence Engine - An Active Defense PowerShell Framework for Phishing Defense with Office 365☆180Updated 4 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆149Updated last week
- This was code for analyzing round 1 of the MITRE Enterprise ATT&CK Evaluation. Please check out https://github.com/joshzelonis/Enterprise…☆95Updated 4 years ago
- A threat hunting / data analysis environment based on Python, Pandas, PySpark and Jupyter Notebook.☆241Updated 3 years ago
- Synapse: a Meta Alert Feeder for TheHive, a Security Incident Response Platform☆71Updated last year
- Samples code that uses QRadar API's☆200Updated 4 years ago