chan2git / splunk-botsLinks
This repository is dedicated to hosting personal comprehensive walkthrough solutions for Splunk's Boss of the SOC (BOTS) CTF-style labs. To be eventually updated with all BOTS events.
☆13Updated last year
Alternatives and similar repositories for splunk-bots
Users that are interested in splunk-bots are comparing it to the libraries listed below
Sorting:
- Tools to automatically create a SANS index based off the course pdf files.☆115Updated 5 years ago
- This repository contains Splunk queries to hunt some anomalies☆44Updated 3 years ago
- A list of Splunk queries that I've collected and used over time.☆87Updated 5 years ago
- Generate Indexes from SANS PDFs☆18Updated last year
- This repository is a comprehensive collection of resources, documentation, apps, and add-ons related to Splunk, a powerful data analytics…☆23Updated 3 weeks ago
- Home for Splunk security datasets.☆126Updated 5 years ago
- Security Onion + Automation + Response Lab including n8n and Velociraptor☆112Updated 3 years ago
- WISKESS automates the Windows evidence processing for Incident Response investigations. Rust version.☆14Updated last month
- An opensource sigma conversion tool built using pysigma☆149Updated last month
- Incident Response documents and tooling☆109Updated 2 months ago
- Shell script to download apps from Splunkbase☆23Updated 5 years ago
- A repository of my own Sigma detection rules.☆162Updated this week
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated 2 months ago
- Splunk Boss of the SOC version 3 dataset.☆392Updated 5 years ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆289Updated last week
- Re-play Adversarial Techniques☆48Updated 4 years ago
- RBA is Splunk's method to aggregate low-fidelity security events as interesting observations tagged with security metadata to create high…☆61Updated this week
- Run Velociraptor on Security Onion☆40Updated 3 years ago
- Tools for simulating threats☆197Updated 2 years ago
- Convert Sigma rules to Wazuh rules☆73Updated 2 months ago
- Indexes for SANS Courses and GIAC Certifications☆266Updated last year
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆67Updated last year
- Harness the power of Splunk for your investigations☆143Updated last month
- SIEGMA - Transform Sigma rules into SIEM consumables☆157Updated 8 months ago
- Docker image for Velocidex Velociraptor☆141Updated 8 months ago
- Real-time Response scripts and schema☆119Updated last month
- Dettectinator - The Python library to your DeTT&CT YAML files.☆118Updated 7 months ago
- An automated Adversary Emulation lab with terraform and MCP server. Build Caldera techniques and operations assisted with LLMs. Built f…☆203Updated last week
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆166Updated last month
- Collection of Jupyter Notebooks by @fr0gger_☆185Updated last month