davidljohnson / SigGen
☆12Updated 8 months ago
Alternatives and similar repositories for SigGen:
Users that are interested in SigGen are comparing it to the libraries listed below
- ☆100Updated 7 months ago
- ☆39Updated this week
- Anvilogic Forge☆88Updated last week
- pocket guide for core detection engineering concepts☆27Updated last year
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆64Updated 8 months ago
- Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help det…☆49Updated 7 months ago
- A community event for security researchers to share their favorite notebooks☆107Updated 11 months ago
- ☆91Updated 2 years ago
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆104Updated 2 months ago
- Synthetic Adversarial Log Objects: A Framework for synthentic log generation☆77Updated last year
- ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit l…☆153Updated last month
- OSSEM Common Data Model☆55Updated 2 years ago
- Dettectinator - The Python library to your DeTT&CT YAML files.☆107Updated this week
- ☆65Updated 7 months ago
- Cloud Analytics helps defenders detect attacks to their cloud infrastructure by developing behavioral analytics for cloud platforms as we…☆52Updated last year
- Intel Retrieval Augmented Generation (RAG) Utilities☆89Updated 11 months ago
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆98Updated 3 months ago
- ☆86Updated 4 months ago
- ☆33Updated last week
- ☆17Updated 3 years ago
- Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )☆167Updated 4 months ago
- This repository hosts community contributed Kestrel huntflows (.hf) and huntbooks (.ipynb)☆31Updated last year
- Collects a listing of MITRE ATT&CK Techniques, then discovers Splunk ESCU detections for each technique☆65Updated 10 months ago
- A POC to implement Detection-as-Code with Terraform and Sumo Logic.☆25Updated last year
- OSSEM Data Dictionaries☆59Updated 5 months ago
- Attack Range to test detection against nativel serverless cloud services and environments☆35Updated 3 years ago
- Open Threat-Informed Detection Engineering☆28Updated last week
- DeRF (Detection Replay Framework) is an "Attacks As A Service" framework, allowing the emulation of offensive techniques and generation o…☆88Updated last year
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆50Updated 2 years ago