HASecuritySolutions / flare
An analytical framework for network traffic and behavioral analytics
☆22Updated 2 years ago
Alternatives and similar repositories for flare:
Users that are interested in flare are comparing it to the libraries listed below
- Web interface for monitoring and interacting with Netflow data stored in Silk repositories.☆13Updated 5 years ago
- Snapshot, patch, health-check, and potentially roll-back Windows VMs☆34Updated 7 years ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- A few quick recipes for those that do not have much time during the day☆22Updated 4 months ago
- incident response scripts☆19Updated 6 years ago
- Sharing Threat Hunting runbooks☆25Updated 5 years ago
- Acheron is a RESTful vulnerability assessment and management framework built around search and dedicated to terminal extensibility.☆32Updated 2 years ago
- Tool used to perform threat intelligence against packet data☆35Updated last month
- ☆30Updated 6 years ago
- Repo of python/bash scripts for identifying IoC's in threat feed and other online tools☆26Updated 4 years ago
- Defence Against the Dark Arts☆34Updated 5 years ago
- ☆21Updated last year
- ☆16Updated 4 years ago
- Incident Response Playbooks☆14Updated 5 years ago
- Docker Container to deploy Mitre Caldera Automated Adversary Emulation System☆26Updated 4 years ago
- These are some of the commands which I use frequently during Malware Analysis and DFIR.☆24Updated last year
- Presentation Slides and Video links☆32Updated 3 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆23Updated 3 years ago
- A completely unsupported set of scripts used in SANS FOR572, Advanced Network Forensics and Analysis☆26Updated 3 months ago
- Create alerts in The Hive from your Graylog alerts, to be turned into Hive cases.☆44Updated 4 years ago
- FireEye iSIGHT Alert Feeder for TheHive, an Open Source and Free Security Incident Response Platform☆16Updated 6 years ago
- ☆12Updated 5 years ago
- PowerSponse is a PowerShell module focused on targeted containment and remediation during incident response.☆38Updated 2 years ago
- Generic Signature Format for SIEM Systems☆14Updated 3 years ago
- MailSniper is a penetration testing tool for searching through email in a Microsoft Exchange environment for specific terms (passwords, i…☆22Updated 3 years ago
- A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns by leveraging Windows Events and Sys…☆12Updated 7 years ago
- PowerShell Memory Pulling script☆19Updated 9 years ago
- Log aggregation, analysis, alerting and correlation for Windows, Syslog and text based logs.☆24Updated 8 years ago
- Best practices in threat intelligence☆46Updated 2 years ago
- Indices for courses in SANS' Network Security Operations curriculum☆15Updated 9 years ago