defenxor / dsiem
Security event correlation engine for ELK stack
☆434Updated 4 months ago
Related projects ⓘ
Alternatives and complementary repositories for dsiem
- DFIRTrack - The Incident Response Tracking Application☆482Updated 2 months ago
- PatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform☆244Updated this week
- Create actionable data from your Vulnerability Scans☆1,356Updated last year
- Actionable analytics designed to combat threats☆972Updated 2 years ago
- Documentation of TheHive☆392Updated last year
- MISP Docker (XME edition)☆283Updated 11 months ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆776Updated last year
- A set of Zeek scripts to detect ATT&CK techniques.☆563Updated 4 months ago
- Documentation of Cortex☆170Updated last year
- Detecting ATT&CK techniques & tactics for Linux☆256Updated 4 years ago
- Extract and aggregate threat intelligence.☆830Updated 9 months ago
- DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.☆538Updated 2 years ago
- Cortex Analyzers Repository☆433Updated this week
- PatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform☆147Updated 2 years ago
- Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search☆429Updated last week
- Suricata and Snort IDS rule and pcap testing system☆449Updated 2 weeks ago
- SIEM Tactics, Techiques, and Procedures☆584Updated 2 weeks ago
- A collection of red team and adversary emulation resources developed and released by MITRE.☆491Updated 3 years ago
- Python Script to access ATT&CK content available in STIX via a public TAXII server☆556Updated 5 months ago
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,137Updated last year
- A (nearly) production ready Dockered MISP☆230Updated 9 months ago
- Elemental - An ATT&CK Threat Library☆314Updated last year
- PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform☆625Updated last week
- Automated Use Case Testing☆165Updated 6 years ago
- Zeek-Formatted Threat Intelligence Feeds☆343Updated this week
- Suricata IDS/IPS log analytics using the Elastic Stack.☆231Updated 3 years ago
- Phantom Community Playbooks☆471Updated 2 weeks ago
- A curated Cyber "Security Orchestration, Automation and Response (SOAR)" awesome list.☆805Updated 2 months ago
- Praetorian's public release of our Metasploit automation of MITRE ATT&CK™ TTPs☆718Updated 4 years ago
- A knowledge base of actionable Incident Response techniques☆612Updated 2 years ago