TheHive-Project / docs
Official documentation for TheHive Project applications
☆21Updated last year
Alternatives and similar repositories for docs:
Users that are interested in docs are comparing it to the libraries listed below
- TheHiveIRPlaybook is a collection of TheHive case templates used for Incident Response☆13Updated 4 years ago
- Repo for Automations and other solutions for Elastic SIEM/Security.☆19Updated 3 years ago
- PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Pac…☆95Updated 3 years ago
- ☆41Updated 9 months ago
- Actionable data for Security Operations☆18Updated 3 years ago
- A few quick recipes for those that do not have much time during the day☆22Updated 3 months ago
- A tool to modify timestamps in a packet capture to a user selected date☆31Updated 3 years ago
- Simple Powershell scripts to collect all Windows Event Logs from a host and parse them into one CSV timeline.☆33Updated 6 years ago
- Documentation used for Shuffle☆19Updated this week
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆35Updated 2 years ago
- THOR Thunderstorm Collectors☆24Updated 4 months ago
- Threat intelligence and threat detection indicators (IOC, IOA)☆53Updated 4 years ago
- Build a domain with three quick PowerShell scripts!☆28Updated 4 years ago
- PowerSponse is a PowerShell module focused on targeted containment and remediation during incident response.☆38Updated 2 years ago
- Some portable tools, some YARA, some Python, and a little bit of love. Not all of these tools can be used in incident response. Use PEs…☆34Updated last year
- Triage automation for suspect URLs☆12Updated 5 years ago
- OpenIOC rules to facilitate hunting for indicators of compromise☆38Updated 3 years ago
- Automatic detection engineering technical state compliance☆53Updated 6 months ago
- A collection of useful PowerShell tools to collect, organize, and visualize Sysmon event data☆39Updated 4 years ago
- Microsoft GPO Readiness Lateral Movement Detection Tool☆16Updated 2 years ago
- This repository contains a script created by Truesec CSIRT team which can be used to identify signs of compromise and to some extent, mit…☆11Updated 3 years ago
- Enumerate Microsoft 365 Groups in a tenant with their metadata☆52Updated 3 years ago
- Workflows for Shuffle☆21Updated 2 years ago
- This repository aims to collect and document indicators from the different C2's listed in the C2-Matrix☆72Updated 3 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆68Updated last year
- This repo contains information on how to auto deploy Sysmon via GPO and Task Scheduler☆12Updated 3 years ago
- ☆14Updated 3 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆23Updated 3 years ago
- This package allows the use of a custom Elastalert Alert which creates alerts with observables in TheHive using TheHive4Py.☆27Updated 3 years ago
- Corelight@Home script☆40Updated last year