LogCraftIO / logcraft-cliLinks
Detection-as-Code CI/CD pipeline for modern security operations (SIEM, EDR, XDR, ...)
☆22Updated 7 months ago
Alternatives and similar repositories for logcraft-cli
Users that are interested in logcraft-cli are comparing it to the libraries listed below
Sorting:
- ☆28Updated last month
- This repository is a comprehensive collection of resources, documentation, apps, and add-ons related to Splunk, a powerful data analytics…☆24Updated 2 weeks ago
- ☆47Updated 3 years ago
- Pulls IOCs from MISP and adds the to reference sets in QRadar☆34Updated 2 years ago
- ☆53Updated last year
- The Enhanced MITRE ATT&CK® Coverage Tracker is an Excel tool for SOCs to measure and improve detection coverage of cyber threats. It simp…☆32Updated last month
- ☆40Updated 2 years ago
- A list of Splunk queries that I've collected and used over time.☆89Updated 5 years ago
- Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs☆55Updated 2 years ago
- A collection of Cortex Analyzers and Responders for TheHive/Cortex☆13Updated 5 years ago
- The Project can be used to integrate QRadar with MISP Threat Sharing Platform☆40Updated 3 years ago
- Cybersecurity Incident Response Plan☆109Updated 5 years ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆67Updated last year
- An opensource sigma conversion tool built using pysigma☆153Updated last week
- ☆67Updated 2 years ago
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆114Updated last year
- SentinelOne STAR Rules☆69Updated 10 months ago
- MISP to Splunk Enterprise Security Theat Intelligence Framework Integration☆14Updated 2 years ago
- Synthetic Adversarial Log Objects: A Framework for synthentic log generation☆85Updated last year
- A repository of my own Sigma detection rules.☆162Updated last month
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆51Updated 7 months ago
- RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high…☆61Updated last week
- A tool that allows you to document and assess any security automation in your SOC☆48Updated last year
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated 3 months ago
- MISP to Sentinel integration☆79Updated 3 weeks ago
- Dettectinator - The Python library to your DeTT&CT YAML files.☆119Updated 8 months ago
- ☆88Updated 9 months ago
- A collection of various SIEM rules relating to malware family groups.☆70Updated last year
- ☆15Updated 4 months ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆157Updated 9 months ago