cea-sec / openwec
An implementation of a Windows Event Collector server running on GNU/Linux.
☆66Updated this week
Alternatives and similar repositories for openwec:
Users that are interested in openwec are comparing it to the libraries listed below
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆37Updated 2 years ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆72Updated this week
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆73Updated last year
- The core backend server handling API requests and task management☆33Updated 2 weeks ago
- pySigma Elasticsearch backend☆48Updated this week
- The Sigma command line interface based on pySigma☆141Updated 2 weeks ago
- A pySigma wrapper to manage detection rules.☆34Updated last month
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆52Updated 2 months ago
- LOKI2 - Simple IOC and YARA Scanner☆84Updated 5 months ago
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆66Updated this week
- Zeek Extension to Collect Metadata for Profiling of Endpoints and Proxies☆27Updated 10 months ago
- Custom Splunk search command to reconstruct a pstree from Sysmon process creation events (EventCode 1)☆23Updated last year
- A repository to share publicly available Velociraptor detection content☆124Updated this week
- Harvest Linux forensic data for operational triage of an event.☆50Updated 7 months ago
- A collection of tips for using MISP.☆74Updated last month
- Cerebrate is an open-source platform meant to act as a trusted contact information provider and interconnection orchestrator for other se…☆85Updated last month
- pySigma Splunk backend☆34Updated last month
- Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indi…☆100Updated 3 months ago
- Elastic Security Labs releases☆55Updated 2 months ago
- The Dissect module tying all other Dissect modules together. It provides a programming API and command line tools which allow easy access…☆50Updated this week
- Anything Sysmon related from the MSTIC R&D team☆148Updated 7 months ago
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆20Updated 3 months ago
- Augmentation to Machine Readable CTI☆27Updated last month
- Powershell module for VMWare vSphere forensics☆146Updated 2 months ago
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆36Updated last year
- gmsad manages Active Directory group Managed Service Account (gMSA) on Linux☆27Updated 3 weeks ago
- An opensource sigma conversion tool built using pysigma☆112Updated 3 weeks ago
- ☆32Updated 2 months ago
- Forensic Artifact Collection Tool Matrix☆79Updated 2 months ago
- Lightweight Python-Based Malware Analysis Pipeline☆30Updated this week