bricerenaud / xdr_yara_rule_matching
custom Python script to perform Yara matching in Cortex XDR
☆12Updated 3 years ago
Alternatives and similar repositories for xdr_yara_rule_matching:
Users that are interested in xdr_yara_rule_matching are comparing it to the libraries listed below
- ESXi Cyber Security Incident Response Script☆22Updated 4 months ago
- Contains compiled binaries of Volatility☆31Updated last week
- Placeholder for my detection repo and misc detection engineering content☆43Updated last year
- ☆20Updated 2 years ago
- CarbonBlack EDR detection rules and response actions☆71Updated 4 months ago
- Sigma detection rules for hunting with the threathunting-keywords project☆52Updated this week
- A home for detection content developed by the delivr.to team☆64Updated last week
- ShellSweeping the evil.☆52Updated 7 months ago
- orc2timeline extracts and analyzes artifacts contained in archives generated with DFIR-ORC.exe to create a timeline from them☆32Updated 2 months ago
- This project is an Ansible Role to execute Atomic Red Team tests against multiple machines by wrapping Invoke-AtomicRedTeam☆25Updated 6 months ago
- ☆22Updated this week
- Simple PowerShell script to enable process scanning with Yara.☆91Updated 2 years ago
- Providing Azure pipelines to create an infrastructure and run Atomic tests.☆50Updated last year
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆75Updated last year
- Jupyter Notebooks for Cyber Threat Intelligence☆35Updated last year
- simple webapp for converting sigma rules into siem queries using the pySigma library☆47Updated last year
- Library of threat hunts to get any user started!☆41Updated 4 years ago
- A few XDR Scripts☆17Updated 3 weeks ago
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆20Updated 3 months ago
- A specification and style guide for YARA rules☆44Updated 11 months ago
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆15Updated last year
- ☆11Updated 2 years ago
- C2 Active Scanner☆52Updated 7 months ago
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆50Updated last month
- Active C&C Detector☆152Updated last year
- An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.☆21Updated 2 years ago
- Create a cool process tree like https://twitter.com/ACEResponder.☆34Updated last year
- Script to automate Linux live evidence collection☆27Updated 2 years ago
- Rapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence…☆56Updated last month
- SkillAegis is a platform to design, run, and monitor exercise scenarios, enhancing skills in applications like MISP and training users in…☆22Updated 2 months ago