Stage2Sec / sigmalint
A simple linter for Sigma rules
☆12Updated 4 years ago
Alternatives and similar repositories for sigmalint:
Users that are interested in sigmalint are comparing it to the libraries listed below
- A Splunk app to use MISP in background☆110Updated 2 weeks ago
- JSON schemas for validating CACAO Security Playbooks. Note: In December 2023, Cyentific AS offered and transferred the content of this re…☆18Updated last year
- Sigma Detection Rule Repository☆87Updated 4 years ago
- Security Monitoring Resolution Categories☆138Updated 3 years ago
- Tool to extract indicators of compromise from security reports in PDF format☆71Updated 8 months ago
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆109Updated 3 months ago
- stix-icons is a collection of colourful and clean icons for use in software, training and marketing material to visualize cyber threats a…☆34Updated 2 years ago
- MISP-STIX-Converter - Python library to handle the conversion between MISP and STIX formats☆53Updated this week
- Import specific data sources into the Sigma generic and open signature format.☆77Updated 2 years ago
- Pulls IOCs from MISP and adds the to reference sets in QRadar☆33Updated last year
- A web application for generating, parsing and validating, manipulating, and visualizing CACAO v2.0 playbooks.☆26Updated 2 months ago
- Collection of useful, up to date, Carbon Black Response Queries☆83Updated 4 years ago
- ☆93Updated 2 years ago
- Analyze binaries collected in VMware Carbon Black EDR against Yara rules.☆37Updated 2 years ago
- ☆42Updated 4 years ago
- Mark Baggett's (@MarkBaggett - GSE #15, SANS SEC573 Author) tool for detecting randomness using NLP techniques rather than pure entropy c…☆125Updated 2 years ago
- Repository of public reference frameworks for the DFIR community.☆115Updated last year
- An open source platform to support analysts to organise their case and tasks☆66Updated 2 weeks ago
- Dump of organized knowledge on DFIR☆133Updated 3 years ago
- Open source training materials for law-enforcement and organisations interested in DFIR.☆56Updated last month
- Carbon Black Feeds☆72Updated last year
- Recon Hunt Queries☆76Updated 3 years ago
- ☆32Updated last year
- A Splunk App containing Sigma detection rules, which can be updated from a Git repository.☆108Updated 5 years ago
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated last month
- Sunburst IOCs for Splunk Ingest☆18Updated 4 years ago
- Converts Sigma detection rules to a Splunk alert configuration.☆109Updated 4 years ago
- ☆5Updated 4 months ago
- Risk Based Alerting Supporting Add-On (SA) for Splunk☆45Updated 3 years ago
- Cerebrate is an open-source platform meant to act as a trusted contact information provider and interconnection orchestrator for other se…☆85Updated 2 months ago