These are open source rules that can be utilized with QRadar to detect various types of threats in the environment.
☆60Jun 11, 2019Updated 7 years ago
Alternatives and similar repositories for QRCE-Rules
Users that are interested in QRCE-Rules are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Integrate IBM QRadar and RPA to automate security L1 tasks.☆14May 20, 2022Updated 4 years ago
- Monitor device events using QRadar☆22Sep 17, 2025Updated 11 months ago
- Scripts to automatically import threat intel into QRadar☆14Jun 20, 2019Updated 7 years ago
- NHSuite allows users to efficiently manage their QRadar Network Hierarchy. Utilizing the provided QRadar API, users can seamlessly export…☆26Jan 22, 2024Updated 2 years ago
- Unofficial third-party scripts, playbooks, and content for IBM QRadar & QRadar Community Edition.☆87May 8, 2025Updated last year
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- This repository bundles various utilities and scripts I built for use with IBM QRadar SIEM☆16Jan 30, 2026Updated 7 months ago
- ☆20Oct 23, 2020Updated 5 years ago
- Basic log analysis tool to detect impossible travel via IP address geographic information☆20Apr 29, 2019Updated 7 years ago
- Scripts and lists to help generate YARA friendly string mutations☆23Apr 9, 2023Updated 3 years ago
- “Intelliroot Code Injection Hunter” is a tool that can to help you identify injected malicious code. The tool can identify and extract po…☆16Sep 21, 2022Updated 3 years ago
- Collection of scripts/resources/ideas for attack surface reduction and additional logging to enable better threat hunting on Windows endp…☆38Apr 5, 2024Updated 2 years ago
- A collection of Sigma rules organized by MITRE ATT&CK technique☆20Apr 1, 2026Updated 5 months ago
- vim, xmonad, xmobar, bashrc, bash profile and inits☆19Aug 8, 2026Updated 3 weeks ago
- Python client for McAfee ePolicy Orchestrator☆15Mar 12, 2021Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- The Project can be used to integrate QRadar with MISP Threat Sharing Platform☆40May 18, 2022Updated 4 years ago
- Volatility plugin to search for all Autostart Extensibility Points (AESPs)☆10Jun 13, 2026Updated 2 months ago
- ☆28Nov 25, 2024Updated last year
- This is a script to import Cisco Talos's IP Blacklist into a Tag (Host Group) within Stealthwatch. This will also optionally create a Cu…☆11May 22, 2023Updated 3 years ago
- ☆10Jan 23, 2023Updated 3 years ago
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆444May 21, 2026Updated 3 months ago
- A repository to share contributions related to TheHive Project☆23Sep 15, 2021Updated 4 years ago
- Repository for SPEED SIEM Use Case Framework☆60May 2, 2020Updated 6 years ago
- All about ransomware notes and extension files.☆14Aug 26, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Example scripts and rules for use in Resilient playbooks.☆36Dec 15, 2023Updated 2 years ago
- Provides an advanced baseline to implement a secure Windows auditing strategy on Windows OS.☆70Feb 22, 2026Updated 6 months ago
- Security event correlation engine for ELK stack☆446Aug 19, 2026Updated 2 weeks ago
- Download a list of suspected malicious IPs and Domains. Create a QRadar Reference Set. Search Your Environment For Malicious IPs☆68Aug 13, 2021Updated 5 years ago
- This Guidance helps customers assess their foundational security setup in their AWS account☆24Oct 19, 2024Updated last year
- not an exploit or a poc☆16Apr 15, 2022Updated 4 years ago
- Windows HTTP协议栈远程代码执行漏洞 CVE-2021-31166☆19Nov 4, 2021Updated 4 years ago
- FIles and guides related to using Elasticstack as a SIEM☆12May 16, 2020Updated 6 years ago
- QRadar AQL backend for converting Sigma rules to QRadar AQL queries☆14Sep 18, 2025Updated 11 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Collection of Jupyter Notebook for Threat Hunting and Blue Team Purposes☆22Jun 15, 2022Updated 4 years ago
- Useful resources about phishing email analysis☆89Jan 31, 2025Updated last year
- Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma☆27Jun 20, 2023Updated 3 years ago
- Integration between MISP platform and McAfee MVISION EDR☆14Mar 14, 2022Updated 4 years ago
- This is a Ansible script for building a ready to go Cuckoo Sandbox server.☆26Mar 22, 2018Updated 8 years ago
- Getting FREE Cyber Security Resources have been a challenge always. Access Davy-Jones-Locker to get all what you might need to upskill yo…☆63Mar 22, 2021Updated 5 years ago
- Generic Signature Format for SIEM Systems☆18Jul 25, 2023Updated 3 years ago