SecSamDev / sysmon-arangodbLinks
Threat hunting with Sysmon and ArangoDB Graphs
☆12Updated 5 years ago
Alternatives and similar repositories for sysmon-arangodb
Users that are interested in sysmon-arangodb are comparing it to the libraries listed below
Sorting:
- A forensic evidence acquirer☆86Updated 4 years ago
- Threat Mapping Catalogue☆18Updated 4 years ago
- A document tagging library☆30Updated 6 months ago
- A list of IOCs applicable to PoshC2☆24Updated 5 years ago
- Joystick is a tool that gives you the ability to transform the ATT&CK Evaluations data into concise views that brings forward the nuances…☆64Updated 2 years ago
- A CALDERA plugin for ATT&CK Evaluations Round 1☆33Updated 2 years ago
- Tracking APT IOCs☆25Updated 4 years ago
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Updated 3 years ago
- A CALDERA plugin☆79Updated last week
- Analytics for Accounting logs from Network devices☆18Updated 4 years ago
- ☆41Updated 3 years ago
- Tool to read EVTX files including SYSMON and convert to JSON, MISP Objects and Graph stream☆12Updated 4 years ago
- This is a repository that is meant to hold detections for various process injection techniques.☆34Updated 5 years ago
- Active C2 IoCs☆99Updated 2 years ago
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆76Updated 3 years ago
- ☆53Updated 6 years ago
- ☆46Updated 2 years ago
- Automatic detection engineering technical state compliance☆55Updated last year
- A CALDERA plugin☆69Updated last week
- A repository of Sysmon For Linux configuration modules☆15Updated 4 years ago
- Yara station is a management portal for Neo23x0-Loki. The mission is to transform the standalone nature of the Loki scanner into a centra…☆36Updated 3 years ago
- ☆44Updated 3 months ago
- Old home of LimaCharlie, open source EDR☆32Updated 2 years ago
- Bro integration with osquery☆15Updated 2 years ago
- A set of YARA rules for the AIL framework to detect leak or information disclosure☆38Updated 8 months ago
- IcedID Decryption Tool☆28Updated 4 years ago
- Links to malware-related YARA rules☆15Updated 3 years ago
- ☆28Updated 4 years ago
- A tool to assess data quality, built on top of the awesome OSSEM.☆79Updated 3 years ago
- A simple command line program to help defender test their detections for network beacon patterns and domain fronting☆70Updated 3 years ago