OTRF / OSSEM-DD
OSSEM Data Dictionaries
☆59Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for OSSEM-DD
- Dettectinator - The Python library to your DeTT&CT YAML files.☆104Updated this week
- Full of public notes and Utilities☆87Updated last week
- A community event for security researchers to share their favorite notebooks☆106Updated 9 months ago
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆35Updated 11 months ago
- ☆70Updated last month
- ☆85Updated 9 months ago
- ☆62Updated this week
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆88Updated 2 years ago
- Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help det…☆45Updated 5 months ago
- OSSEM Detection Model☆168Updated 2 years ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆68Updated last year
- Library of threat hunts to get any user started!☆40Updated 4 years ago
- Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques☆123Updated 9 months ago
- Remote access and Antivirus Logging Database☆41Updated 6 months ago
- OSSEM Common Data Model☆54Updated 2 years ago
- ☆1Updated last month
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects…☆38Updated 4 years ago
- pySigma Splunk backend☆34Updated 7 months ago
- ATT&CK Powered Suit is a browser extension that puts the complete MITRE ATT&CK® knowledge base at your fingertips with text search, conte…☆73Updated 2 weeks ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆141Updated last year
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆66Updated last week
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆81Updated last month
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆109Updated 11 months ago
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆49Updated 3 weeks ago
- Cloud Templates and scripts to deploy mordor environments☆128Updated 3 years ago
- Anything Sysmon related from the MSTIC R&D team☆146Updated 5 months ago
- A repository of my own Sigma detection rules.☆156Updated 2 months ago
- Collects a listing of MITRE ATT&CK Techniques, then discovers Splunk ESCU detections for each technique☆65Updated 8 months ago