Splunk App to assist Sysmon Threat Hunting
☆37Mar 7, 2017Updated 9 years ago
Alternatives and similar repositories for app_splunk_sysmon_hunter
Users that are interested in app_splunk_sysmon_hunter are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆13Feb 6, 2018Updated 8 years ago
- Sysmon Splunk App☆48Sep 16, 2026Updated last week
- Mass Triage Tools☆20Sep 9, 2026Updated 2 weeks ago
- Powershell scripts using CyCLI.☆10May 22, 2019Updated 7 years ago
- Splunk app for Threat hunting☆15Nov 15, 2018Updated 7 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Deploy and maintain Symon through the Splunk Deployment Sever☆32Jul 30, 2020Updated 6 years ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆945Dec 12, 2023Updated 2 years ago
- A series of Bro Scripts created for detection purposes.☆19Nov 18, 2016Updated 9 years ago
- Maps process creation logged by Sysmon uses Google Org Chart API☆23Mar 5, 2016Updated 10 years ago
- Detecting DNS Spoofing, DNS Tunneling, DNS Exfiltration☆36Sep 28, 2015Updated 10 years ago
- Powershell Functions to interact with TheHive-Project☆11Jun 27, 2019Updated 7 years ago
- Examples for the CyCLI Powershell module☆12Mar 8, 2019Updated 7 years ago
- A set of Splunk workflow action definitions to export field values to CyberChef for further analysis.☆13Jan 22, 2018Updated 8 years ago
- Qakbot Registry Key Configuration Decryptor☆14Dec 20, 2021Updated 4 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- ☆15Jan 10, 2019Updated 7 years ago
- Pragmatic Network Security for Cloud and Hybrid Networks☆10Nov 24, 2015Updated 10 years ago
- Python scripts to download, parse, and enrich scans.io study data and load into Splunk for research, threat intelligence gathering, and s…☆20Aug 12, 2026Updated last month
- OG Atomic Red Team☆30Jun 12, 2018Updated 8 years ago
- Sysmon Tools for PowerShell☆233Aug 17, 2018Updated 8 years ago
- Sharing my BITS☆13Feb 23, 2018Updated 8 years ago
- Splunk app for visualization of DMARC RUA mails☆15Sep 26, 2025Updated 11 months ago
- InvestigationPlaybookSpec☆70Sep 26, 2017Updated 8 years ago
- Finding SSL Blindspots for Red Teams☆34Jul 28, 2020Updated 6 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Repository of yara rules☆60Nov 29, 2022Updated 3 years ago
- This module installs and configures MISP (Malware Information Sharing Platform)☆14Apr 14, 2026Updated 5 months ago
- A Docker container for Moloch based on minimal Debian☆26Jan 25, 2016Updated 10 years ago
- LNK to JSON☆14Mar 7, 2019Updated 7 years ago
- A Logstash grok filter to parse and tokenize the message field of Windows eventlog entries.☆12May 10, 2016Updated 10 years ago
- ☆20Dec 19, 2017Updated 8 years ago
- Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsac…☆891Nov 17, 2020Updated 5 years ago
- Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into …☆830Nov 5, 2023Updated 2 years ago
- Clean public password dump files and store in ELK☆36Jan 24, 2018Updated 8 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- This is a repository from Adam Swan and I's presentation on Windows Logs Zero 2 Hero.☆22Jan 30, 2018Updated 8 years ago
- InsecurePowerShell is PowerShell with some security features removed.☆105Dec 19, 2017Updated 8 years ago
- Inject DLL Prototype using Microsoft.Windows.ACTCTX COM Object☆21Feb 16, 2017Updated 9 years ago
- Fake SMB and SAMR data☆12Oct 27, 2019Updated 6 years ago
- Simple Windows Event Log Forwarder (SWELF). Its easy to use/simply works Log Forwarder and EVTX Parser. Almost in full release here at ht…☆25May 13, 2026Updated 4 months ago
- Add-on for ingesting DMARC aggregate reports into Splunk☆15Dec 5, 2022Updated 3 years ago
- attack2jira automates the process of standing up a Jira environment that can be used to track and measure ATT&CK coverage☆114Mar 26, 2023Updated 3 years ago