chan2git / splunk-botsLinks
This repository is dedicated to hosting personal comprehensive walkthrough solutions for Splunk's Boss of the SOC (BOTS) CTF-style labs. To be eventually updated with all BOTS events.
☆15Updated 2 years ago
Alternatives and similar repositories for splunk-bots
Users that are interested in splunk-bots are comparing it to the libraries listed below
Sorting:
- Tools to automatically create a SANS index based off the course pdf files.☆121Updated 5 years ago
- A list of Splunk queries that I've collected and used over time.☆90Updated 5 years ago
- A template for writing a condensed course index leveraging LaTeX indexing☆114Updated last week
- This repository is a comprehensive collection of resources, documentation, apps, and add-ons related to Splunk, a powerful data analytics…☆24Updated this week
- Blue Team detection lab created with Terraform and Ansible in Azure.☆176Updated last year
- Generate Indexes from SANS PDFs☆18Updated last year
- This repository contains Splunk queries to hunt some anomalies☆46Updated 3 years ago
- Shell script to download apps from Splunkbase☆23Updated 5 years ago
- Incident Response documents and tooling☆111Updated last month
- Indexes for SANS Courses and GIAC Certifications☆276Updated last year
- Real-time Response scripts and schema☆121Updated 3 months ago
- Run Velociraptor on Security Onion☆40Updated 3 years ago
- Rules generated from our investigations.☆203Updated 7 months ago
- ☆47Updated 3 years ago
- A repository of my own Sigma detection rules.☆163Updated 2 months ago
- Home for Splunk security datasets.☆126Updated 5 years ago
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆408Updated 2 months ago
- Harness the power of Splunk for your investigations☆148Updated 3 months ago
- Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques☆142Updated last year
- SIEGMA - Transform Sigma rules into SIEM consumables☆158Updated 10 months ago
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated 4 months ago
- Tools for simulating threats☆199Updated 2 years ago
- SPL cheatsheet for Splunk.☆26Updated 3 years ago
- ☆96Updated 3 weeks ago
- Web based S1 query navigator for one-click threat hunting☆24Updated 5 years ago
- Splunk Boss of the SOC version 3 dataset.☆402Updated 5 years ago
- A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon☆214Updated 5 years ago
- Docker image for Velocidex Velociraptor☆143Updated last month
- An opensource sigma conversion tool built using pysigma☆157Updated last week
- MISP Playbooks☆222Updated 3 months ago