bluemountaincyber / building-detections-aws
☆15Updated last year
Alternatives and similar repositories for building-detections-aws:
Users that are interested in building-detections-aws are comparing it to the libraries listed below
- ☆13Updated last year
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆72Updated 11 months ago
- ☆93Updated 2 years ago
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆111Updated 5 months ago
- A preconfigured Velociraptor triage collector☆51Updated this week
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆198Updated 7 months ago
- ☆42Updated 2 years ago
- Cloud Analytics helps defenders detect attacks to their cloud infrastructure by developing behavioral analytics for cloud platforms as we…☆53Updated 2 years ago
- Notes on responding to security breaches relating to Azure AD☆110Updated 3 years ago
- ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit l…☆162Updated last month
- Conference presentations☆47Updated last year
- Automating Security Detection Engineering, published by Packt☆54Updated 6 months ago
- ☆42Updated 4 years ago
- ☆12Updated last year
- Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs☆53Updated last year
- DeRF (Detection Replay Framework) is an "Attacks As A Service" framework, allowing the emulation of offensive techniques and generation o…☆92Updated last year
- A guide to using Azure Data Explorer and KQL for DFIR☆102Updated 2 years ago
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆77Updated 11 months ago
- An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.☆55Updated 3 years ago
- ☆41Updated 11 months ago
- ADXFlowmaster helps SecOps teams Threat Hunt suspicious network traffic inside & outside of Azure.☆36Updated 5 months ago
- A list of Splunk queries that I've collected and used over time.☆80Updated 4 years ago
- Practical Threat Detection Engineering, Published by Packt☆68Updated last year
- Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.☆133Updated 2 years ago
- Identify Azure blobs using a wordlist of account name and container name strings☆40Updated last month
- SPL cheatsheet for Splunk.☆21Updated 2 years ago
- Content Repo for Demystifying KQL Tutorial Series☆69Updated 7 months ago
- A collection of various SIEM rules relating to malware family groups.☆66Updated 10 months ago
- A collection of ARM-based detections for Azure/AzureAD based TTPs☆85Updated last year
- A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon☆201Updated 4 years ago