bluemountaincyber / building-detections-aws
☆15Updated last year
Related projects ⓘ
Alternatives and complementary repositories for building-detections-aws
- ☆13Updated 9 months ago
- Conference presentations☆47Updated last year
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆97Updated this week
- ☆41Updated 2 years ago
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆62Updated 6 months ago
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆75Updated 6 months ago
- ☆87Updated 2 years ago
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆179Updated 2 months ago
- Notes on responding to security breaches relating to Azure AD☆96Updated 2 years ago
- MISP to Sentinel integration☆60Updated this week
- Distribution of the SANS SEC504 Windows Cheat Sheet Lab☆66Updated 4 years ago
- Identify Azure blobs using a wordlist of account name and container name strings☆32Updated 3 years ago
- Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.☆125Updated 2 years ago
- Serverless AWS application to upload and hash evidence files.☆19Updated 2 years ago
- A collection of various SIEM rules relating to malware family groups.☆62Updated 5 months ago
- ADXFlowmaster helps SecOps teams Threat Hunt suspicious network traffic inside & outside of Azure.☆27Updated 3 weeks ago
- ☆12Updated last year
- ☆52Updated last year
- A dataset containing Office 365 Unified Audit Logs for security research and detection☆48Updated 2 years ago
- A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon☆193Updated 4 years ago
- 2021 SANS DFIR Summit: Greppin' Logs☆21Updated 3 years ago
- Audit Inspector is a tool for configuring and auditing Windows auditing.☆32Updated last month
- A list of Splunk queries that I've collected and used over time.☆72Updated 4 years ago
- SPL cheatsheet for Splunk.☆20Updated last year
- Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting☆57Updated 3 weeks ago
- Docker Crash Course: How to containerize your favorite security tools☆27Updated last year
- Reflex SOAR☆12Updated 2 years ago
- Creating a resource to help build and manage an Insider Threat program.☆62Updated 7 months ago
- Misc. content for Microsoft Sentinel☆17Updated 7 months ago
- This is the One Stop place where you can find almost all of your Tools of Requirements in DFIR☆71Updated 2 years ago