cudeso / misp2defenderLinks
MISP to Microsoft Defender integration
☆16Updated this week
Alternatives and similar repositories for misp2defender
Users that are interested in misp2defender are comparing it to the libraries listed below
Sorting:
- Advanced Threat Hunting: Ransomware Group☆29Updated 7 months ago
- MISP to Sentinel integration☆79Updated last week
- KQLIntel is a browser-based tool that uses LLMs to convert threat intelligence reports into actionable Kusto Query Language (KQL) queries…☆28Updated 6 months ago
- Menu for Thor scanner lite☆20Updated 3 months ago
- A repository to share publicly available Velociraptor detection content☆196Updated this week
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆89Updated last year
- Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting☆68Updated 2 months ago
- A preconfigured Velociraptor triage collector☆74Updated last month
- Pipeline that allows sending forensic artifacts to OpenRelik for automatic processing☆40Updated last week
- Generates a detailed CSV file containing Sigma Rules statistics for each service or category, and each level, offering a holistic view of…☆10Updated 2 years ago
- ☆105Updated 7 months ago
- A repository of my own Sigma detection rules.☆163Updated 2 months ago
- Config files for my GitHub profile.☆14Updated 2 years ago
- A repository to help CTI teams tackle the challenges around collection and research by providing guidance from experienced practitioners☆115Updated last year
- SentinelOne STAR Rules☆71Updated last year
- A collection of various SIEM rules relating to malware family groups.☆70Updated last year
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆77Updated last year
- MAES: M365 Analyzer & Extractor Suite Po☆33Updated this week
- Knowing which rule should trigger according to the redcannary test☆11Updated last year
- Hunting Queries for Defender ATP☆83Updated last month
- ☆96Updated last month
- ☆54Updated last year
- Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or eve…☆277Updated last month
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆55Updated last week
- An automated deployment tool that creates instrumented Azure environments with vulnerable systems for simulating attacks and testing Micr…☆61Updated 6 months ago
- ☆44Updated 2 months ago
- An opensource sigma conversion tool built using pysigma☆157Updated 3 weeks ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆300Updated this week
- Some important DFIR Resources☆84Updated 2 years ago
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆16Updated this week