amrandazz / cloud-threat-detection
Cloud threat detection visualization from excalidraw
☆12Updated 2 years ago
Alternatives and similar repositories for cloud-threat-detection:
Users that are interested in cloud-threat-detection are comparing it to the libraries listed below
- Repository with supporting materials for Invictus Academy/Training☆42Updated 2 months ago
- A collection of ARM-based detections for Azure/AzureAD based TTPs☆84Updated last year
- Cloud Analytics helps defenders detect attacks to their cloud infrastructure by developing behavioral analytics for cloud platforms as we…☆53Updated last year
- Azure Activity Log Axe is a continually developing tool that simplifies the transactional log format provided by Microsoft. The tool leve…☆26Updated 6 months ago
- ☆41Updated 2 weeks ago
- Welcome to the Cloud Security Toolkit repository, your all-in-one destination for cutting-edge cloud security resources! Whether you're d…☆20Updated last week
- Solution to deploy a Sentinel playground demo environment☆57Updated last year
- ADXFlowmaster helps SecOps teams Threat Hunt suspicious network traffic inside & outside of Azure.☆34Updated 4 months ago
- ☆26Updated last year
- This repository contains the research and components of our research into using Sigma for AWS Incident Response.☆27Updated last year
- Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs☆52Updated last year
- ☆28Updated 4 months ago
- A POC to implement Detection-as-Code with Terraform and Sumo Logic.☆27Updated last year
- GitHub action for validating Microsoft Sentinel detection rules☆13Updated last year
- Knowledge Report Alert & Normalization Generator☆27Updated 11 months ago
- A guide to simplify the process of evaluating Datadog's Cloud SIEM security capabilities to detect AWS threats.☆18Updated last year
- When good OAuth apps go rogue. Documents observed OAuth application tradecraft☆68Updated 2 months ago
- Collection of Microsoft Identity Threat Detection and Response resources.☆40Updated last week
- ☆42Updated 11 months ago
- Queries from the blog posts.☆16Updated 5 months ago
- ☆45Updated 2 weeks ago
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆35Updated 3 weeks ago
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆67Updated 10 months ago
- Security Scripts and Sources for daily usage.☆54Updated last month
- ☆72Updated 4 months ago
- Programming Microsoft Sentinel book☆25Updated last year
- AWS EKS Cluster Forensics☆23Updated 3 years ago
- ThreatModel for Azure Storage - Library of all the attack scenarios on Azure Storage, and how to mitigate them following a risk-based app…☆57Updated last year
- REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.☆32Updated last month