Yamato-Security / suzaku-rulesLinks
☆12Updated 2 weeks ago
Alternatives and similar repositories for suzaku-rules
Users that are interested in suzaku-rules are comparing it to the libraries listed below
Sorting:
- The Eventlog Compendium is the go-to resource for understanding Windows Event Logs.☆51Updated 8 months ago
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆163Updated 3 weeks ago
- Rules shared by the community from 100 Days of YARA 2025☆37Updated 11 months ago
- Turn any blog into structured threat intelligence.☆43Updated this week
- Repository that contains a set of purposefully erroneous Yara rules.☆61Updated 5 months ago
- ☆18Updated 3 weeks ago
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆31Updated 2 years ago
- ☆52Updated 2 weeks ago
- A preconfigured Velociraptor triage collector☆74Updated last month
- When good OAuth apps go rogue. Documents observed OAuth application tradecraft☆82Updated 2 weeks ago
- Sigma detection rules for hunting with the threathunting-keywords project☆57Updated 9 months ago
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆53Updated last year
- ☆28Updated 2 months ago
- Anvilogic Forge☆113Updated 3 months ago
- pocket guide for core detection engineering concepts☆31Updated 2 years ago
- Convert Sigma rules to SIEM queries, directly in your browser.☆107Updated last week
- 🐻❄️ 🏹 Threat hunting with Polars and flaws.cloud AWS CloudTrail datasets.☆14Updated last year
- A preconfigured Windows-based system designed for rapid forensic investigations in both Azure and AWS.☆39Updated last year
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆89Updated last month
- Cyber Threat Intelligence☆68Updated 3 weeks ago
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆51Updated 7 months ago
- Short deep dive into Threat Hunting on AWS☆15Updated 2 years ago
- TTPMapper is an AI-driven threat intelligence parser that converts unstructured reports whether from web URLs or PDF files into structure…☆48Updated 6 months ago
- ☆21Updated last year
- An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.☆60Updated 3 years ago
- ☆100Updated 2 weeks ago
- VelociraptorMCP is a Model Context Protocol bridge for exposing LLMs to MCP clients.☆65Updated 4 months ago
- Sample evtx files to use for testing hayabusa detection rules☆63Updated last month
- Quick ESXi Log Parser☆28Updated 2 months ago
- A tool for fetching DFIR and other GitHub tools.☆24Updated 4 months ago