Security-Onion-Solutions / securityonion-soc
☆53Updated last week
Alternatives and similar repositories for securityonion-soc:
Users that are interested in securityonion-soc are comparing it to the libraries listed below
- ☆48Updated 2 weeks ago
- Sysmon and wazuh integration with Sigma sysmon rules [updated]☆65Updated 3 years ago
- ☆19Updated 3 years ago
- Run Velociraptor on Security Onion☆37Updated 2 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆70Updated last year
- A Ruleset to enhance detection capabilities of Ossec using Sysmon☆92Updated 3 years ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆35Updated 2 years ago
- ☆88Updated last week
- A CALDERA plugin☆76Updated last month
- Fast IOC and YARA Scanner☆79Updated 5 years ago
- Pathfinder is a plugin for mapping network vulnerabilities, scanned by CALDERA or imported by a supported network scanner, and translatin…☆126Updated 3 weeks ago
- Collection of walkthroughs on various threat hunting techniques☆75Updated 4 years ago
- MITRE Engage™ is a framework for conducting Denial, Deception, and Adversary Engagements.☆63Updated last year
- ☆65Updated 3 years ago
- ☆51Updated 3 years ago
- Collection of Suricata rule sets that I use modified to my environments.☆39Updated 4 years ago
- ☆43Updated 2 years ago
- Convert Sigma rules to Wazuh rules☆64Updated last year
- Cyber Threat Intelligence Data, Indicators, and Analysis☆84Updated 4 months ago
- Import CrowdStrike Threat Intelligence into your instance of MISP☆46Updated last month
- ☆34Updated 4 years ago
- Library of threat hunts to get any user started!☆44Updated 4 years ago
- Security Onion + Automation + Response Lab including n8n and Velociraptor☆109Updated 2 years ago
- Further investigation in to APT campaigns disclosed by private security firms and security agencies☆86Updated 2 years ago
- Repository for SPEED SIEM Use Case Framework☆53Updated 4 years ago
- PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Pac…☆95Updated 3 years ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆51Updated 2 years ago
- ☆68Updated 2 months ago
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆106Updated 2 years ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆63Updated 2 years ago