IBM / qradar-monitor-device-events
Monitor device events using QRadar
☆21Updated last year
Related projects ⓘ
Alternatives and complementary repositories for qradar-monitor-device-events
- Unofficial third-party scripts, playbooks, and content for IBM QRadar & QRadar Community Edition.☆77Updated 3 months ago
- The Project can be used to integrate QRadar with MISP Threat Sharing Platform☆38Updated 2 years ago
- Integrate IBM QRadar and RPA to automate security L1 tasks.☆14Updated 2 years ago
- Synapse: a Meta Alert Feeder for TheHive, a Security Incident Response Platform☆71Updated last year
- Using QRadar API☆20Updated 6 years ago
- Example scripts and rules for use in Resilient playbooks.☆34Updated 10 months ago
- Source code for IBM SOAR Apps that are available on our App Exchange☆91Updated 2 weeks ago
- Community driven repository of Playbooks and Apps for ThreatConnect.☆69Updated 3 months ago
- SOC Workflow App helps Security Analysts and Threat Hunters explore suspicious events, look into raw events arriving at the Elastic Stack…☆92Updated 2 years ago
- A Splunk App containing Sigma detection rules, which can be updated from a Git repository.☆107Updated 4 years ago
- A collection of notebooks built for defensive and offensive operations.☆76Updated 4 years ago
- OASIS Cyber Threat Intelligence (CTI) TC Open Repository: Convert STIX 1.2 XML to STIX 2.x JSON☆49Updated 6 months ago
- Cyber Threat Intelligence - Toolbox☆50Updated 6 years ago
- This repo represents work the Phantom Community collaborates on to build apps and learn.☆12Updated 3 years ago
- ☆58Updated last year
- The Infosec Community Definitive Guide to Jupyter Notebooks☆115Updated 4 years ago
- Wazuh - Splunk App☆50Updated last month
- Rapid cybersecurity toolkit based on Elastic in Docker. Designed to quickly build elastic-based environments to analyze and execute threa…☆18Updated 4 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated last week
- STIX 2.1 Data Modeling Tool☆25Updated 4 months ago
- These workflows are provided for sample usage, new submissions and updates from the community, and are NOT supported by IBM.☆46Updated last week
- This repository bundles various utilities and scripts I built for use with IBM QRadar SIEM☆15Updated 2 years ago
- Threat Intelligence with Elastic - Minemeld integration with Elasticsearch☆19Updated 3 years ago
- ☆131Updated 7 months ago
- ☆29Updated 3 years ago
- Playbooks designed for IBM SOAR developed by The IR Gurus. These playbooks can be used to demonstrate how to design playbooks, perform au…☆13Updated 6 months ago
- Threat Hunting with ELK Workshop (InfoSecWorld 2017)☆66Updated 7 years ago
- Definition, description and relationship types of MISP objects☆91Updated this week
- Developer documentation for Resilient APIs☆24Updated 3 weeks ago