SigmaHQ / pySigma-backend-elasticsearch
pySigma Elasticsearch backend
☆48Updated this week
Alternatives and similar repositories for pySigma-backend-elasticsearch:
Users that are interested in pySigma-backend-elasticsearch are comparing it to the libraries listed below
- pySigma Splunk backend☆34Updated last month
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆72Updated this week
- ☆33Updated last month
- Automated YARA Rule Standardization and Quality Assurance Tool☆179Updated last week
- The Sigma command line interface based on pySigma☆141Updated 2 weeks ago
- An opensource sigma conversion tool built using pysigma☆112Updated 3 weeks ago
- Dettectinator - The Python library to your DeTT&CT YAML files.☆107Updated this week
- Sigma rules to share with the community☆115Updated 3 months ago
- Elastic Security Labs releases☆55Updated 2 months ago
- A guide on how to write fast and memory friendly YARA rules☆127Updated last year
- BlackBerry Threat Research & Intelligence☆96Updated last year
- A repository of my own Sigma detection rules.☆156Updated 4 months ago
- Sigma rule specification☆119Updated last week
- Forensic Artifact Collection Tool Matrix☆79Updated 2 months ago
- Rules generated from our investigations.☆188Updated 2 months ago
- ☆63Updated last month
- A pySigma wrapper to manage detection rules.☆34Updated last month
- A repository to share publicly available Velociraptor detection content☆124Updated this week
- Rules Shared by the Community from 100 Days of YARA 2023☆77Updated last year
- ☆86Updated 4 months ago
- JPCERT/CC public YARA rules repository☆106Updated last month
- OSSEM Data Dictionaries☆59Updated 4 months ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆73Updated last year
- YARA rule analyzer to improve rule quality and performance☆95Updated 3 weeks ago
- ☆97Updated last month
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆52Updated 2 months ago
- ATT&CK Powered Suit is a browser extension that puts the complete MITRE ATT&CK® knowledge base at your fingertips with text search, conte…☆74Updated 2 months ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆59Updated 8 months ago
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆100Updated 4 months ago
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆136Updated this week