SentineLabs / S1QL-Queries
☆52Updated last year
Related projects ⓘ
Alternatives and complementary repositories for S1QL-Queries
- Repository of SentinelOne Deep Visibility queries.☆119Updated 3 years ago
- SentinelOne STAR Rules☆50Updated last year
- ☆1Updated 3 weeks ago
- Notes on responding to security breaches relating to Azure AD☆96Updated 2 years ago
- ☆70Updated last month
- Full of public notes and Utilities☆86Updated this week
- A repository to share publicly available Velociraptor detection content☆119Updated this week
- MISP to Sentinel integration☆60Updated this week
- MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity☆86Updated 3 years ago
- ☆26Updated 3 years ago
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆94Updated last year
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆75Updated 6 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆76Updated last week
- ☆41Updated 2 years ago
- ☆75Updated 3 weeks ago
- A collection of various SIEM rules relating to malware family groups.☆62Updated 5 months ago
- Real-time Response scripts and schema☆104Updated 11 months ago
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆36Updated 2 years ago
- Detection of obfuscated Powershell commands☆54Updated last year
- This repository contains Splunk queries to hunt some anomalies☆38Updated 2 years ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆109Updated 11 months ago
- 2021 SANS DFIR Summit: Greppin' Logs☆21Updated 3 years ago
- ☆50Updated 6 months ago
- A script that updates KAPE (using Get-KAPEUpdate.ps1) as well as EZ Tools (within .\KAPE\Modules\bin) and the ancillary files that enhanc…☆53Updated last year
- ☆80Updated 2 months ago
- Collection of scripts/resources/ideas for attack surface reduction and additional logging to enable better threat hunting on Windows endp…☆38Updated 7 months ago
- Conference presentations☆47Updated last year
- Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting☆57Updated 3 weeks ago
- Audit Inspector is a tool for configuring and auditing Windows auditing.☆32Updated last month
- User Feedback Space of #MitreAssistant☆37Updated last year