cisagov / ioc-scannerLinks
Search a filesystem for indicators of compromise (IoC).
☆81Updated this week
Alternatives and similar repositories for ioc-scanner
Users that are interested in ioc-scanner are comparing it to the libraries listed below
Sorting:
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆80Updated 2 months ago
- The Infosec Community Definitive Guide to Jupyter Notebooks☆130Updated 5 years ago
- ☆73Updated 2 years ago
- A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.☆245Updated 8 months ago
- ☆88Updated 9 months ago
- Passive service locator, a python sniffer that identifies servers, clients, names and much more☆257Updated 2 years ago
- CrowdStrike's Open Source Policy & Contribution Guide☆47Updated 3 weeks ago
- Creating a hardened "Blue Forest" with Server 2016/2019 Domain Controllers☆265Updated last year
- A GeoIP lookup utility utilizing ipinfo.io services.☆92Updated 2 years ago
- ☆55Updated 4 years ago
- Digital Forensics Artifacts Knowledge Base☆88Updated this week
- This is a set of tools for doing forensics analysis on Microsoft ESE databases.☆126Updated 3 years ago
- Conference presentations☆60Updated 2 months ago
- Distribution of the SANS SEC504 Windows Cheat Sheet Lab☆76Updated 5 years ago
- Corelight@Home script☆46Updated 2 years ago
- Get all my software☆180Updated 6 months ago
- Dashboard for conducting Backdoors and Breaches sessions over Zoom.☆119Updated last year
- ☆120Updated last month
- Jupyter notebooks for threat hunting☆60Updated 9 months ago
- A list of my personal projects☆177Updated 3 years ago
- ☆94Updated last week
- Security Onion + Automation + Response Lab including n8n and Velociraptor☆112Updated 3 years ago
- Zerofox Alert Feeder for TheHive, an Open Source and Free Security Incident Response Platform☆45Updated 5 years ago
- InsightVM helpful SQL queries☆76Updated 10 months ago
- Collects a listing of MITRE ATT&CK Techniques, then discovers Splunk ESCU detections for each technique☆69Updated last year
- A port of BHIS's Backdoors & Breaches for playingcards.io☆64Updated 2 years ago
- Extracts fields from zeek logs, compatible with zeek-cut☆25Updated last year
- This code snippet retrieves Azure Sentinel rules that are mapped to MITRE ATT&CK Framework and generates the related MITRE D3FEND defense…☆74Updated 4 years ago
- Stand-Alone Windows Hardening (SAWH) is a script to reduce the attack surface of Windows systems that are not attached to a Windows Activ…☆55Updated 4 years ago
- A Windows event logging and collection baseline focused on finding balance between forensic value and optimising retention.☆290Updated 4 years ago