Neo23x0 / auditd
Best Practice Auditd Configuration
☆1,541Updated 3 months ago
Alternatives and similar repositories for auditd:
Users that are interested in auditd are comparing it to the libraries listed below
- Transform Linux Audit logs for SIEM usage☆730Updated this week
- A Linux Auditd rule set mapped to MITRE's Attack Framework☆777Updated 4 years ago
- Configuration files for the SOF-ELK VM☆1,543Updated this week
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,507Updated 6 months ago
- A repository of sysmon configuration modules☆2,700Updated 4 months ago
- Wazuh - Ruleset☆430Updated 3 months ago
- Linux audit userspace repository☆612Updated this week
- Digging Deeper....☆3,058Updated this week
- NIST Certified SCAP 1.2 toolkit☆1,407Updated this week
- A Suricata based IDS/IPS/NSM distro☆1,502Updated 5 months ago
- Detect Tactics, Techniques & Combat Threats☆2,091Updated last week
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆2,022Updated this week
- Automate the creation of a lab environment complete with security tooling and logging best practices☆4,680Updated 6 months ago
- A utility to safely generate malicious network traffic patterns and evaluate controls.☆1,278Updated 9 months ago
- Create actionable data from your Vulnerability Scans☆1,362Updated 2 years ago
- Security automation content in SCAP, Bash, Ansible, and other formats☆2,302Updated this week
- Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term o…☆2,405Updated 4 months ago
- Simple Bash IOC Scanner☆713Updated 2 years ago
- ☆2,217Updated last year
- Cortex: a Powerful Observable Analysis and Active Response Engine☆1,361Updated 2 months ago
- ☆2,014Updated this week
- YARA signature and IOC database for my scanners and tools☆2,525Updated last month
- A toolset to make a system look as if it was the victim of an APT attack☆2,497Updated last year
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,140Updated last year
- Windows Events Attack Samples☆2,286Updated last year
- Re-play Security Events☆1,618Updated 9 months ago
- A repository for using osquery for incident detection and response☆834Updated 2 years ago
- Your Everyday Threat Intelligence☆1,785Updated this week
- Mapping the MITRE ATT&CK Matrix with Osquery☆784Updated last year
- Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management☆3,084Updated 3 years ago