Threat Hunting with ELK Workshop (InfoSecWorld 2017)
☆65Oct 31, 2017Updated 8 years ago
Alternatives and similar repositories for ELK-Hunting
Users that are interested in ELK-Hunting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- PowerShell Script for Agentless Incident Response☆25Apr 5, 2018Updated 8 years ago
- My personal experience in Threat Hunting and knowledge gained so far.☆19May 27, 2017Updated 9 years ago
- Reference sheet for Threat Hunting Professional Course☆26Mar 10, 2019Updated 7 years ago
- Collection of walkthroughs on various threat hunting techniques☆78Aug 3, 2020Updated 5 years ago
- ThreatHunt is a PowerShell repository that allows you to train your threat hunting skills.☆135Jul 25, 2019Updated 7 years ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- This repository contains all the config files and scripts used for our Open Source Endpoint monitoring project.☆35Jul 8, 2019Updated 7 years ago
- Splunk code (SPL) for serious threat hunters and detection engineers.☆294Jan 15, 2024Updated 2 years ago
- Python script to automatically create sigma rules from The hive observables☆25Mar 17, 2019Updated 7 years ago
- Auxiliary scripts for Incident Response with ELK☆11Oct 7, 2015Updated 10 years ago
- Powershell collection designed to assist in Threat Hunting Windows systems.☆27Apr 13, 2018Updated 8 years ago
- Threat hunting repo for my independent study on threat hunting with OSQuery☆27Jan 16, 2018Updated 8 years ago
- ☆13Feb 6, 2018Updated 8 years ago
- A Windows Event Processing Utility☆47Feb 21, 2018Updated 8 years ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆943Dec 12, 2023Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Powershell Threat Hunting Module☆293Sep 21, 2016Updated 9 years ago
- ATT&CK Remote Threat Hunting Incident Response☆203Dec 8, 2024Updated last year
- Validates yara rules and tries to repair the broken ones.☆42Sep 5, 2020Updated 5 years ago
- A collection of resources for Threat Hunters☆916Oct 15, 2024Updated last year
- This repository contains tools used by 401trg.☆21Apr 14, 2021Updated 5 years ago
- Yara intergrated into BurpSuite☆48Jun 30, 2016Updated 10 years ago
- Automated Real-Time Threat Hunting with ATD, Active Response and Elasticsearch/Kibana☆10Aug 17, 2018Updated 7 years ago
- Configuration files for the SOF-ELK VM☆1,746Updated this week
- ☆53May 21, 2018Updated 8 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Various exploits☆10Apr 27, 2017Updated 9 years ago
- This repo is dedicated to all my tricks, tweaks and modules for testing and hunting threats. This repo contains multiple directories whic…☆57Jan 10, 2018Updated 8 years ago
- ☆80Jun 25, 2019Updated 7 years ago
- ☆23May 7, 2021Updated 5 years ago
- Parser for Windows Scheduled Task files.☆13Apr 26, 2023Updated 3 years ago
- Experimental DNS logs pipeline based on Pi-hole dnsmasq logs, ELK stack, and Filebeat. Sample configs included.☆29Oct 26, 2023Updated 2 years ago
- Exporting MISP event attributes to yara rules usable with Thor apt scanner☆25Mar 27, 2017Updated 9 years ago
- Splunk App to assist Sysmon Threat Hunting☆38Mar 7, 2017Updated 9 years ago
- python script allow red teaming , hackthebox Pwners , OSCP lovers to shorten their time by these useful shells☆32Mar 4, 2021Updated 5 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Ansible playbook to convert Sigma rules to ElastAlert rules☆10Feb 5, 2021Updated 5 years ago
- Cheat sheets for threat hunting, detection and other stuff.☆34Oct 7, 2022Updated 3 years ago
- Technical add-on to ingest json formatted volatility memory analysis plugin outputs☆13May 21, 2018Updated 8 years ago
- Track public endpoints and connections across AWS accounts using VPC Flow Logs☆12Jun 14, 2016Updated 10 years ago
- Python Script to access ATT&CK content available in STIX via a public TAXII server☆571Dec 19, 2025Updated 7 months ago
- ☆26Oct 14, 2017Updated 8 years ago
- An informational repo about hunting for adversaries in your IT environment.☆1,883Nov 17, 2021Updated 4 years ago