christian-taillon / splunk-spl
SPL cheatsheet for Splunk.
☆20Updated last year
Related projects ⓘ
Alternatives and complementary repositories for splunk-spl
- This repository contains Splunk queries to hunt some anomalies☆38Updated 2 years ago
- A list of Splunk queries that I've collected and used over time.☆72Updated 4 years ago
- A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon☆193Updated 4 years ago
- ☆41Updated 2 years ago
- SentinelOne STAR Rules☆50Updated last year
- Tools for simulating threats☆178Updated last year
- ☆24Updated last year
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆179Updated 2 months ago
- ☆52Updated last year
- Cybersecurity Incident Response Plan☆87Updated 4 years ago
- ☆87Updated 2 years ago
- This repository is a comprehensive collection of resources, documentation, apps, and add-ons related to Splunk, a powerful data analytics…☆21Updated this week
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆75Updated 6 months ago
- ☆26Updated 3 years ago
- Repository of public reference frameworks for the DFIR community.☆109Updated last year
- Full of public notes and Utilities☆87Updated last week
- This is the One Stop place where you can find almost all of your Tools of Requirements in DFIR☆72Updated 2 years ago
- A repository of my own Sigma detection rules.☆156Updated 2 months ago
- Creating a resource to help build and manage an Insider Threat program.☆62Updated 7 months ago
- Repository of SentinelOne Deep Visibility queries.☆119Updated 3 years ago
- Notes on responding to security breaches relating to Azure AD☆96Updated 2 years ago
- Repository of attack and defensive information for Business Email Compromise investigations☆230Updated 2 months ago
- BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.☆41Updated last year
- MISP to Sentinel integration☆60Updated last week
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆81Updated last month
- A dataset containing Office 365 Unified Audit Logs for security research and detection☆48Updated 2 years ago
- Resources To Learn And Understand SIGMA Rules☆169Updated last year
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆97Updated this week
- A collection of various SIEM rules relating to malware family groups.☆62Updated 5 months ago