amitn322 / blackeskLinks
BLACK ESK SIEM is a SIEM platform built with Elasticsearch, Syslog-Ng and Kibana
☆28Updated 2 years ago
Alternatives and similar repositories for blackesk
Users that are interested in blackesk are comparing it to the libraries listed below
Sorting:
- Defence Against the Dark Arts☆34Updated 5 years ago
- ELKFH - Elastic, Logstash, Kibana, Filebeat and Honeypot (HTTP, HTTPS, SSH, RDP, VNC, Redis, MySQL, MONGO, SMB, LDAP)☆46Updated 4 years ago
- Cyber Analytics Platform and Examination System (CAPES) Project Page☆14Updated 3 years ago
- Corelight@Home script☆42Updated last year
- Snapshot, patch, health-check, and potentially roll-back Windows VMs☆34Updated 7 years ago
- A Zeek Network Security Monitor tutorial that will cover the basics of creating a Zeek instance on your network in addition to all of the…☆62Updated 2 years ago
- An analytical framework for network traffic and behavioral analytics☆22Updated 2 years ago
- Powershell Scripts to work on Crowdstrike Falcon that pull back raw data relevant to forensic investigation☆23Updated 6 months ago
- Ransomware Simulator for Red/Blue teams to test their defences.☆19Updated 3 years ago
- ☆34Updated 4 years ago
- Repo for Automations and other solutions for Elastic SIEM/Security.☆18Updated 4 years ago
- Terraform scripts for deploying OpenCTI to AWS, Azure, and GCP☆31Updated last year
- The Project can be used to integrate QRadar with MISP Threat Sharing Platform☆39Updated 3 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆70Updated 2 years ago
- A few quick recipes for those that do not have much time during the day☆22Updated 7 months ago
- unix_collector is a Live Response collection script for Incident Response on UNIX-like systems using native binaries. Supports AIX, Andro…☆35Updated 2 weeks ago
- Kibana 6 Templates for Suricata IDPS Threat Hunting☆24Updated 6 years ago
- A script to create and assign SOP tasks into the cases☆20Updated 4 years ago
- ☆29Updated 7 years ago
- Incident Response Network Tools☆24Updated 3 years ago
- Rapid cybersecurity toolkit based on Elastic in Docker. Designed to quickly build elastic-based environments to analyze and execute threa…☆18Updated 5 years ago
- Sharing Threat Hunting runbooks☆26Updated 5 years ago
- Cyber Threat Intelligence Appliance☆13Updated 2 years ago
- Hunting Newly Registered Domains☆10Updated 6 years ago
- Lua plugin to extract data from Wireshark and convert it into MISP format☆48Updated last year
- Sysmon Tools for PowerShell☆12Updated 6 years ago
- 🚀 IRIS-SOAR: Modular SOAR (Security Orchestration, Automation, and Response) implementation in Python. Designed to complement DFIR-IRIS …☆10Updated last year
- Ansible role for installing Sysmon with popular config files included.☆25Updated 2 years ago
- A tool to modify timestamps in a packet capture to a user selected date☆31Updated 3 years ago
- Lokix Platform is a free open-source solution to help blue teams and threat hunters use Loki Scanner to sweep enterprise networks☆25Updated 4 years ago