bfuzzy / auditd-attack
A Linux Auditd rule set mapped to MITRE's Attack Framework
☆788Updated 4 years ago
Alternatives and similar repositories for auditd-attack:
Users that are interested in auditd-attack are comparing it to the libraries listed below
- Mapping the MITRE ATT&CK Matrix with Osquery☆793Updated last year
- A repository for using osquery for incident detection and response☆847Updated 2 years ago
- An information security preparedness tool to do adversarial simulation.☆1,122Updated 6 years ago
- ☆1,072Updated 6 years ago
- Praetorian's public release of our Metasploit automation of MITRE ATT&CK™ TTPs☆722Updated 5 years ago
- Create actionable data from your Vulnerability Scans☆1,379Updated 2 years ago
- Actionable analytics designed to combat threats☆982Updated 2 years ago
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,156Updated last year
- Detecting ATT&CK techniques & tactics for Linux☆258Updated 4 years ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆917Updated last year
- Re-play Security Events☆1,639Updated last year
- A curated list of awesome resources related to Mitre ATT&CK™ Framework☆600Updated 5 years ago
- Utilities for MITRE™ ATT&CK☆1,027Updated 11 months ago
- A utility to safely generate malicious network traffic patterns and evaluate controls.☆1,306Updated last year
- Open Source Security Events Metadata (OSSEM)☆1,266Updated 2 years ago
- Online hash checker for Virustotal and other services☆825Updated last month
- Detect Tactics, Techniques & Combat Threats☆2,152Updated last week
- Documentation of TheHive☆397Updated last year
- Incident Response Methodologies☆1,025Updated 6 years ago
- Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into …☆801Updated last year
- Security event correlation engine for ELK stack☆439Updated 10 months ago
- Elemental - An ATT&CK Threat Library☆318Updated 2 years ago
- Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsac…☆866Updated 4 years ago
- Modular file scanning/analysis framework☆619Updated 5 years ago
- Virtual Machine for Adversary Emulation and Threat Hunting☆1,273Updated 3 months ago
- FAME Automates Malware Evaluation☆895Updated 3 weeks ago
- Cyber Analytics Repository☆935Updated last year
- Deception based detection techniques mapped to the MITRE’s ATT&CK framework☆289Updated 7 years ago
- The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).☆544Updated 2 years ago
- A Python package to interact with the Mitre ATT&CK Framework☆477Updated last year