Stage2Sec / sigmalintLinks
A simple linter for Sigma rules
☆13Updated 4 years ago
Alternatives and similar repositories for sigmalint
Users that are interested in sigmalint are comparing it to the libraries listed below
Sorting:
- A Splunk app to use MISP in background☆110Updated last month
- Feed Generator for MISP☆19Updated 2 years ago
- Pulls IOCs from MISP and adds the to reference sets in QRadar☆34Updated 2 years ago
- Sigma Detection Rule Repository☆89Updated 5 years ago
- Recon Hunt Queries☆77Updated 4 years ago
- ☆42Updated 4 years ago
- Security Monitoring Resolution Categories☆138Updated 3 years ago
- Carbon Black Feeds☆73Updated 2 years ago
- Risk Based Alerting Supporting Add-On (SA) for Splunk☆45Updated 3 years ago
- Analyze binaries collected in VMware Carbon Black EDR against Yara rules.☆38Updated 2 years ago
- ☆95Updated 2 years ago
- Collection of useful, up to date, Carbon Black Response Queries☆83Updated 4 years ago
- Tool to extract indicators of compromise from security reports in PDF format☆72Updated last year
- Converts Sigma detection rules to a Splunk alert configuration.☆111Updated 5 years ago
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated last week
- JSON schemas for validating CACAO Security Playbooks. Note: In December 2023, Cyentific AS offered and transferred the content of this re…☆19Updated last year
- An open source platform to support analysts to organise their case and tasks☆84Updated 2 weeks ago
- ☆32Updated last year
- 2021 SANS DFIR Summit: Greppin' Logs☆20Updated 3 years ago
- BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.☆42Updated 2 years ago
- Scripts for TheHive.☆23Updated 5 years ago
- stix-icons is a collection of colourful and clean icons for use in software, training and marketing material to visualize cyber threats a…☆34Updated 2 years ago
- This is a python tool aiming to make using TheHive webhooks easier.☆28Updated 4 years ago
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆37Updated 3 years ago
- MISP-STIX-Converter - Python library to handle the conversion between MISP and STIX formats☆55Updated this week
- ☆19Updated 3 years ago
- Dump of organized knowledge on DFIR☆134Updated 3 years ago
- A utility repo to assist with converting between MISP and STIX formats☆68Updated 4 years ago
- ATT&CK Remote Threat Hunting Incident Response☆200Updated 6 months ago
- Resources for SANS CTI Summit 2020 presentation☆19Updated 5 years ago