SigmaHQ / pySigma-backend-elasticsearch
pySigma Elasticsearch backend
☆53Updated last week
Alternatives and similar repositories for pySigma-backend-elasticsearch:
Users that are interested in pySigma-backend-elasticsearch are comparing it to the libraries listed below
- The Sigma command line interface based on pySigma☆152Updated 3 weeks ago
- pySigma Splunk backend☆38Updated 2 months ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆80Updated this week
- An opensource sigma conversion tool built using pysigma☆125Updated 4 months ago
- Dettectinator - The Python library to your DeTT&CT YAML files.☆111Updated last month
- Sigma rules to share with the community☆120Updated 3 months ago
- YARA rule analyzer to improve rule quality and performance☆99Updated 3 weeks ago
- yara detection rules for hunting with the threathunting-keywords project☆116Updated 2 months ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆77Updated last year
- A MITRE Caldera plugin☆43Updated 5 months ago
- ATT&CK Powered Suit is a browser extension that puts the complete MITRE ATT&CK® knowledge base at your fingertips with text search, conte…☆77Updated 2 weeks ago
- Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques☆132Updated last year
- Convert Sigma rules to SIEM queries, directly in your browser.☆74Updated this week
- Active C&C Detector☆154Updated last year
- ☆87Updated 2 months ago
- ☆68Updated 2 months ago
- A repository of my own Sigma detection rules.☆158Updated 8 months ago
- FJTA (Forensic Journal Timeline Analyzer) is a tool that analyzes Linux filesystem (EXT4, XFS) journals (not systemd-journald), generates…☆63Updated last month
- OSSEM Data Dictionaries☆59Updated 3 months ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆149Updated last month
- Takajō (鷹匠) is a Hayabusa results analyzer.☆116Updated this week
- A pySigma wrapper to manage detection rules.☆38Updated 3 weeks ago
- ☆27Updated 4 years ago
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆172Updated this week
- The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the hos…☆31Updated 3 years ago
- OSSEM Detection Model☆178Updated 2 years ago
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆153Updated 2 months ago
- Elastic Security Labs releases☆63Updated last month
- A guide on how to write fast and memory friendly YARA rules☆142Updated 2 months ago
- Validates Sigma rules using the JSON schema☆16Updated last year