Splunk App to assist Sysmon Threat Hunting
☆38Mar 7, 2017Updated 9 years ago
Alternatives and similar repositories for app_splunk_sysmon_hunter
Users that are interested in app_splunk_sysmon_hunter are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆13Feb 6, 2018Updated 8 years ago
- Sysmon Splunk App☆47Aug 21, 2018Updated 7 years ago
- Deploy and maintain Symon through the Splunk Deployment Sever☆32Jul 30, 2020Updated 5 years ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆942Dec 12, 2023Updated 2 years ago
- Mass Triage Tools☆20Mar 10, 2026Updated 3 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- A series of Bro Scripts created for detection purposes.☆19Nov 18, 2016Updated 9 years ago
- Maps process creation logged by Sysmon uses Google Org Chart API☆23Mar 5, 2016Updated 10 years ago
- Splunk app for Threat hunting☆15Nov 15, 2018Updated 7 years ago
- Detecting DNS Spoofing, DNS Tunneling, DNS Exfiltration☆36Sep 28, 2015Updated 10 years ago
- Powershell scripts using CyCLI.☆10May 22, 2019Updated 7 years ago
- Powershell Functions to interact with TheHive-Project☆11Jun 27, 2019Updated 6 years ago
- Examples for the CyCLI Powershell module☆12Mar 8, 2019Updated 7 years ago
- ☆16May 20, 2022Updated 4 years ago
- A set of Splunk workflow action definitions to export field values to CyberChef for further analysis.☆13Jan 22, 2018Updated 8 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Qakbot Registry Key Configuration Decryptor☆14Dec 20, 2021Updated 4 years ago
- Pragmatic Network Security for Cloud and Hybrid Networks☆10Nov 24, 2015Updated 10 years ago
- ☆15Jan 10, 2019Updated 7 years ago
- A Python Script that, when run, checks your Plex server for recently added and summarizes the entries within the time frame you specify. …☆12Jun 20, 2021Updated 4 years ago
- Python scripts to download, parse, and enrich scans.io study data and load into Splunk for research, threat intelligence gathering, and s…☆20May 20, 2026Updated 3 weeks ago
- OG Atomic Red Team☆29Jun 12, 2018Updated 8 years ago
- Sysmon Tools for PowerShell☆233Aug 17, 2018Updated 7 years ago
- Sharing my BITS☆13Feb 23, 2018Updated 8 years ago
- Repository of yara rules☆60Nov 29, 2022Updated 3 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- InvestigationPlaybookSpec☆70Sep 26, 2017Updated 8 years ago
- Splunk app for visualization of DMARC RUA mails☆15Sep 26, 2025Updated 8 months ago
- Finding SSL Blindspots for Red Teams☆34Jul 28, 2020Updated 5 years ago
- A Docker container for Moloch based on minimal Debian☆26Jan 25, 2016Updated 10 years ago
- This module installs and configures MISP (Malware Information Sharing Platform)☆14Apr 14, 2026Updated 2 months ago
- ☆20Dec 19, 2017Updated 8 years ago
- Clean public password dump files and store in ELK☆36Jan 24, 2018Updated 8 years ago
- Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsac…☆887Nov 17, 2020Updated 5 years ago
- A Logstash grok filter to parse and tokenize the message field of Windows eventlog entries.☆12May 10, 2016Updated 10 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into …☆826Nov 5, 2023Updated 2 years ago
- Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at ht…☆24May 13, 2026Updated last month
- Data exfiltration using reflective DNS resolution covert channel☆53Jan 10, 2018Updated 8 years ago
- This is a repository from Adam Swan and I's presentation on Windows Logs Zero 2 Hero.☆22Jan 30, 2018Updated 8 years ago
- InsecurePowerShell is PowerShell with some security features removed.☆105Dec 19, 2017Updated 8 years ago
- Technical add-on to ingest json formatted volatility memory analysis plugin outputs☆13May 21, 2018Updated 8 years ago
- Automated Memory Forensic☆34Jul 18, 2018Updated 7 years ago