Security-Onion-Solutions / securityonion-soc
☆49Updated this week
Alternatives and similar repositories for securityonion-soc:
Users that are interested in securityonion-soc are comparing it to the libraries listed below
- Threat Detection & Anomaly Detection rules for popular open-source components☆50Updated 2 years ago
- MITRE Engage™ is a framework for conducting Denial, Deception, and Adversary Engagements.☆62Updated 10 months ago
- ☆48Updated 2 years ago
- ☆34Updated 4 years ago
- Run Velociraptor on Security Onion☆37Updated 2 years ago
- ☆48Updated this week
- ☆18Updated 3 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆68Updated last year
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆34Updated 2 years ago
- Sysmon and wazuh integration with Sigma sysmon rules [updated]☆64Updated 3 years ago
- Library of threat hunts to get any user started!☆42Updated 4 years ago
- A collection of tips for using MISP.☆74Updated 2 months ago
- ☆87Updated this week
- A CALDERA plugin☆74Updated 3 months ago
- Collection of walkthroughs on various threat hunting techniques☆75Updated 4 years ago
- Repo of python/bash scripts for identifying IoC's in threat feed and other online tools☆26Updated 4 years ago
- ☆65Updated 2 weeks ago
- yara detection rules for hunting with the threathunting-keywords project☆101Updated last week
- ☆41Updated 2 years ago
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆104Updated 2 years ago
- Further investigation in to APT campaigns disclosed by private security firms and security agencies☆85Updated 2 years ago
- S2AN - Mapper of Sigma/Suricata Rules/Signatures ➡️ MITRE ATT&CK Navigator☆85Updated 2 years ago
- BlueSploit is a DFIR framework with the main purpose being to quickly capture artifacts for later review.☆32Updated 5 years ago
- Import CrowdStrike Threat Intelligence into your instance of MISP☆42Updated 3 months ago
- Repository for SPEED SIEM Use Case Framework☆53Updated 4 years ago
- A CALDERA plugin☆25Updated 6 months ago
- This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports☆67Updated 2 months ago
- IOCPARSER.COM is a Fast and Reliable service that enables you to extract IOCs and intelligence from different data sources.☆34Updated 3 years ago
- Terraform scripts for deploying OpenCTI to AWS, Azure, and GCP☆31Updated 10 months ago
- A Ruleset to enhance detection capabilities of Ossec using Sysmon☆87Updated 2 years ago