Yamato-Security / suzaku-rulesLinks
☆11Updated this week
Alternatives and similar repositories for suzaku-rules
Users that are interested in suzaku-rules are comparing it to the libraries listed below
Sorting:
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆29Updated 2 years ago
- Suzaku (朱雀) is a sigma-based threat hunting and fast forensics timeline generator for cloud logs.☆146Updated this week
- Quick ESXi Log Parser☆23Updated last week
- pocket guide for core detection engineering concepts☆30Updated 2 years ago
- A preconfigured Velociraptor triage collector☆55Updated this week
- A tool for fetching DFIR and other GitHub tools.☆24Updated last month
- The Eventlog Compendium is the go-to resource for understanding Windows Event Logs.☆48Updated 4 months ago
- ☆17Updated 2 months ago
- Rules shared by the community from 100 Days of YARA 2025☆35Updated 7 months ago
- A preconfigured Windows-based system designed for rapid forensic investigations in both Azure and AWS.☆39Updated last year
- ☆19Updated 3 years ago
- TIM is a Kusto investigation platform that enables a user to quickly pivot between data sources; annotate their findings; and promotes co…☆23Updated last year
- Invictus Threat Intelligence: IOCs and TTPs from blogs, research and more☆12Updated 2 weeks ago
- Python script to walk a folder or a zip file for SQLite Databases☆38Updated last year
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆21Updated 10 months ago
- ☆94Updated last month
- Sigma detection rules for hunting with the threathunting-keywords project☆56Updated 6 months ago
- Repository that contains a set of purposefully erroneous Yara rules.☆58Updated last month
- ☆24Updated 7 months ago
- ☆21Updated 5 months ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆84Updated 3 months ago
- Track progress and keep notes while working through likethecoins' CTI Self Study Plan☆28Updated 3 years ago
- ☆21Updated last year
- my MSTICpy practice and custom tools repository☆11Updated 4 months ago
- Tools and scripts to deploy and manage OpenRelik instances☆15Updated 2 months ago
- USN Journal full path builder☆61Updated 11 months ago
- Finding ClickFix and FakeCAPTCHA like it's 1999☆49Updated this week
- Sample evtx files to use for testing hayabusa detection rules☆59Updated 10 months ago
- The Event Maturity Matrix (EMM) is a comprehensive framework that provides clarity regarding the capabilities and nuances of SaaS audit l…☆22Updated 2 months ago
- An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.☆58Updated 3 years ago