Neo23x0 / auditd
Best Practice Auditd Configuration
☆1,498Updated last month
Related projects ⓘ
Alternatives and complementary repositories for auditd
- Transform Linux Audit logs for SIEM usage☆711Updated 3 weeks ago
- A Linux Auditd rule set mapped to MITRE's Attack Framework☆778Updated 4 years ago
- Linux audit userspace repository☆600Updated last month
- CVE Alerting Platform☆1,806Updated this week
- Create actionable data from your Vulnerability Scans☆1,357Updated last year
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,508Updated 4 months ago
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆1,968Updated this week
- Configuration files for the SOF-ELK VM☆1,496Updated last week
- Cortex: a Powerful Observable Analysis and Active Response Engine☆1,345Updated 3 weeks ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆776Updated last year
- A repository of sysmon configuration modules☆2,664Updated 3 months ago
- Detect Tactics, Techniques & Combat Threats☆2,067Updated 2 weeks ago
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆767Updated last year
- Wazuh - Ruleset☆423Updated 2 months ago
- A curated Cyber "Security Orchestration, Automation and Response (SOAR)" awesome list.☆812Updated 2 months ago
- A tool that allows you to create vulnerable instrumented local or cloud environments to simulate attacks against and collect the data int…☆2,160Updated 2 weeks ago
- NIST Certified SCAP 1.2 toolkit☆1,382Updated last week
- Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term o…☆2,384Updated 2 months ago
- Re-play Security Events☆1,604Updated 8 months ago
- A repository for using osquery for incident detection and response☆828Updated 2 years ago
- ☆2,189Updated last year
- Digging Deeper....☆2,984Updated this week
- VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities a…☆1,396Updated 2 months ago
- The Hunting ELK☆3,769Updated 5 months ago
- Security automation content in SCAP, Bash, Ansible, and other formats☆2,218Updated this week
- Sysmon for Linux☆1,748Updated this week
- A Suricata based IDS/IPS/NSM distro☆1,479Updated 3 months ago
- A utility to safely generate malicious network traffic patterns and evaluate controls.☆1,261Updated 7 months ago
- Open Source Security Events Metadata (OSSEM)☆1,238Updated last year
- Automate the creation of a lab environment complete with security tooling and logging best practices☆4,648Updated 4 months ago