UncoderIO / Roota
Roota is a public-domain language of threat detection and response that combines native queries from a SIEM, EDR, XDR, or Data Lake with standardized metadata and threat intelligence to enable automated translation into other languages
☆121Updated 7 months ago
Alternatives and similar repositories for Roota:
Users that are interested in Roota are comparing it to the libraries listed below
- MISP Playbooks☆184Updated last week
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆140Updated this week
- A repository of my own Sigma detection rules.☆157Updated 5 months ago
- An opensource sigma conversion tool built using pysigma☆115Updated 2 months ago
- CTI Blueprints is a free suite of templates and tools that helps Cyber Threat Intelligence analysts create high-quality, actionable repor…☆223Updated last year
- Dettectinator - The Python library to your DeTT&CT YAML files.☆108Updated last month
- Rules generated from our investigations.☆193Updated 3 months ago
- A library of reference materials, tools, and other resources to aid threat profiling, threat quantification, and cyber adversary defense☆84Updated last year
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆76Updated 8 months ago
- ☆84Updated last week
- ☆93Updated 2 years ago
- Adversarial Interception Mission Oriented Discovery and Disruption Framework, or AIMOD2, is a structured threat hunting approach to proac…☆86Updated last year
- ☆100Updated last month
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆115Updated last year
- Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques☆131Updated 11 months ago
- Harness the power of Splunk for your investigations☆88Updated 2 months ago
- Open Threat-Informed Detection Engineering☆37Updated last month
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆109Updated 3 months ago
- LotL RMM☆128Updated this week
- A repository to share publicly available Velociraptor detection content☆126Updated this week
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆60Updated 9 months ago
- ☆79Updated 2 weeks ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆182Updated 2 weeks ago
- CarbonBlack EDR detection rules and response actions☆71Updated 5 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆84Updated last week
- MISP to Sentinel integration☆62Updated 2 months ago
- Intel Retrieval Augmented Generation (RAG) Utilities☆90Updated last year
- Mapping of open-source detection rules and atomic tests.☆124Updated last month
- The LOLBins CTI-Driven (Living-Off-the-Land Binaries Cyber Threat Intelligence Driven) is a project that aims to help cyber defenders und…☆118Updated 10 months ago
- Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )☆167Updated 5 months ago