defensivedepth / osquery-filters
☆34Updated last year
Alternatives and similar repositories for osquery-filters:
Users that are interested in osquery-filters are comparing it to the libraries listed below
- An experimental Velociraptor implementation using cloud infrastructure☆23Updated this week
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆20Updated 3 months ago
- Accelerating the collection, processing, analysis and outputting of digital forensic artefacts.☆32Updated last month
- Recon Hunt Queries☆76Updated 3 years ago
- A repository of Sysmon For Linux configuration modules☆15Updated 3 years ago
- Send High & New Incidents to The Hive incident management Platform☆18Updated 3 years ago
- Converts Sigma detection rules to a Splunk alert configuration.☆13Updated 3 years ago
- ☆41Updated 9 months ago
- Powershell Scripts to work on Crowdstrike Falcon that pull back raw data relevant to forensic investigation☆22Updated last month
- Automatic detection engineering technical state compliance☆53Updated 6 months ago
- DNS Dashboard for hunting and identifying beaconing☆14Updated 4 years ago
- 🧰 ESXi Testing Tookit is a command-line utility designed to help security teams test ESXi detections.☆19Updated this week
- PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.☆36Updated last year
- Bloodhound Portable for Windows☆51Updated last year
- Library of threat hunts to get any user started!☆41Updated 4 years ago
- General Content☆21Updated 6 months ago
- Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents☆38Updated 8 months ago
- Specific guidance and configuration scripts based on Microsoft-recommended security configuration baselines for Windows.☆11Updated 4 years ago
- A tool to modify timestamps in a packet capture to a user selected date☆31Updated 3 years ago
- A collection of searches, interesting events and tables on Crowdstrike Splunk.☆29Updated 3 years ago
- Incident Response Report Using GitHub-Sphinx☆19Updated 5 years ago
- This project is an Ansible Role to execute Atomic Red Team tests against multiple machines by wrapping Invoke-AtomicRedTeam☆25Updated 6 months ago
- Stupid Simple Detection Testing☆12Updated 10 months ago
- Track progress and keep notes while working through likethecoins' CTI Self Study Plan☆28Updated 2 years ago
- Creates an ATT&CK Navigator map of an Adversary Emulation Plan☆16Updated 3 years ago
- simple webapp for converting sigma rules into siem queries using the pySigma library☆47Updated last year
- ☆40Updated last year
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆36Updated 2 years ago
- ☆14Updated 3 years ago