SigmaHQ / legacy-sigmatoolsLinks
Legacy Sigma Tools (sigmac etc.)
☆15Updated 2 years ago
Alternatives and similar repositories for legacy-sigmatools
Users that are interested in legacy-sigmatools are comparing it to the libraries listed below
Sorting:
- ☆11Updated 2 years ago
- Library of threat hunts to get any user started!☆46Updated 5 years ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆85Updated last week
- ShellSweeping the evil.☆53Updated last year
- A home for detection content developed by the delivr.to team☆73Updated 4 months ago
- Security Content for the PEAK Threat Hunting Framework☆39Updated last year
- simple webapp for converting sigma rules into siem queries using the pySigma library☆51Updated 2 years ago
- ☆22Updated 2 years ago
- Slides of my public talks☆56Updated 2 years ago
- Rhaegal is a tool written in Python 3 used to scan Windows Event Logs for suspicious logs. Rhaegal uses custom rule format to detect sus…☆42Updated 2 years ago
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆38Updated last week
- Placeholder for my detection repo and misc detection engineering content☆42Updated 2 years ago
- Sigma detection rules for hunting with the threathunting-keywords project☆57Updated 9 months ago
- pySigma Splunk backend☆41Updated 3 weeks ago
- Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.☆18Updated 2 years ago
- ATT&CK Powered Suit is a browser extension that puts the complete MITRE ATT&CK® knowledge base at your fingertips with text search, conte…☆80Updated 6 months ago
- ☆36Updated 2 years ago
- ☆21Updated 3 years ago
- Rapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence…☆73Updated last week
- Quick ESXi Log Parser☆28Updated 2 months ago
- Sample evtx files to use for testing hayabusa detection rules☆63Updated last month
- Active C&C Detector☆156Updated 2 years ago
- Simple PowerShell script to enable process scanning with Yara.☆96Updated 3 years ago
- Get-MiniTimeline - Triage Collection and Timeline Generation w/ KAPE☆32Updated last year
- ☆44Updated 5 months ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Updated 3 years ago
- This repository contains OpenIOC rules to aid in hunting for indicators of compromise and TTPs focused on Advanced Persistent Threat grou…☆26Updated 2 years ago
- Initial triage of Windows Event logs☆105Updated last year
- ☆91Updated 4 months ago
- This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports☆75Updated 2 weeks ago