InfoSecInnovations / What2Log
☆39Updated 2 years ago
Alternatives and similar repositories for What2Log:
Users that are interested in What2Log are comparing it to the libraries listed below
- MDE relies on some of the Audit settings to be enabled☆97Updated 2 years ago
- Conference presentations☆47Updated last year
- ☆72Updated 4 months ago
- Audit Inspector is a tool for configuring and auditing Windows auditing.☆32Updated 4 months ago
- ☆41Updated last year
- Pushes Sysmon Configs☆89Updated 3 years ago
- Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations☆83Updated 6 months ago
- A collection of various SIEM rules relating to malware family groups.☆65Updated 8 months ago
- Collection of scripts/resources/ideas for attack surface reduction and additional logging to enable better threat hunting on Windows endp…☆38Updated 10 months ago
- ☆33Updated 2 years ago
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆76Updated 9 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆84Updated last week
- MISP to Sentinel integration☆62Updated 2 months ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆68Updated last year
- A list of RMMs designed to be used in automation to build alerts☆108Updated 3 months ago
- ☆79Updated 2 weeks ago
- ☆46Updated 3 weeks ago
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆36Updated 2 years ago
- SigmaHQ pySigma CrowdStrike processing pipeline☆23Updated 4 months ago
- ☆14Updated 4 months ago
- ☆42Updated 2 years ago
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆35Updated this week
- Full of public notes and Utilities☆97Updated last week
- VirtualGHOST Detection Tool☆89Updated 9 months ago
- Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.☆128Updated 2 years ago
- A PowerShell incident response script for quick triage☆78Updated 2 years ago
- A repository to share publicly available Velociraptor detection content☆126Updated this week
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆112Updated last year
- ☆5Updated 3 months ago
- Open Threat-Informed Detection Engineering☆37Updated last month