chan2git / splunk-botsLinks
This repository is dedicated to hosting personal comprehensive walkthrough solutions for Splunk's Boss of the SOC (BOTS) CTF-style labs. To be eventually updated with all BOTS events.
☆15Updated 2 years ago
Alternatives and similar repositories for splunk-bots
Users that are interested in splunk-bots are comparing it to the libraries listed below
Sorting:
- Tools to automatically create a SANS index based off the course pdf files.☆120Updated 5 years ago
- This repository is a comprehensive collection of resources, documentation, apps, and add-ons related to Splunk, a powerful data analytics…☆24Updated 2 weeks ago
- A list of Splunk queries that I've collected and used over time.☆89Updated 5 years ago
- This repository contains Splunk queries to hunt some anomalies☆46Updated 3 years ago
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated 3 months ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆67Updated last year
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆167Updated last month
- Playbooks-On-Rails for Splunk (PORS)☆16Updated 8 months ago
- Shell script to download apps from Splunkbase☆23Updated 5 years ago
- Rules generated from our investigations.☆203Updated 6 months ago
- Web based S1 query navigator for one-click threat hunting☆24Updated 5 years ago
- Tools for simulating threats☆199Updated 2 years ago
- Convert Sigma rules to Wazuh rules☆73Updated 3 months ago
- Real-time Response scripts and schema☆121Updated 2 months ago
- An opensource sigma conversion tool built using pysigma☆153Updated last week
- Re-play Adversarial Techniques☆51Updated 4 years ago
- Downloading Splunk, made easy through scripts☆24Updated last month
- RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high…☆61Updated last week
- Blue Team detection lab created with Terraform and Ansible in Azure.☆173Updated last year
- Home for Splunk security datasets.☆126Updated 5 years ago
- A repository of my own Sigma detection rules.☆162Updated last month
- Harness the power of Splunk for your investigations☆145Updated 2 months ago
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆403Updated last month
- Splunk Content Control Tool☆124Updated last week
- ☆53Updated last year
- Docker configurations for TheHive, Cortex and 3rd party tools☆128Updated 2 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆157Updated 9 months ago
- Generate Indexes from SANS PDFs☆18Updated last year
- Stand up a simple Elastic container with Kibana, Fleet, and the Detection Engine☆514Updated 3 weeks ago
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆93Updated 6 months ago