defenxor / dsiem
Security event correlation engine for ELK stack
☆439Updated 10 months ago
Alternatives and similar repositories for dsiem:
Users that are interested in dsiem are comparing it to the libraries listed below
- DFIRTrack - The Incident Response Tracking Application☆498Updated 8 months ago
- MISP Docker (XME edition)☆282Updated last year
- Mapping the MITRE ATT&CK Matrix with Osquery☆793Updated last year
- Documentation of TheHive☆397Updated last year
- Suricata, Snort and Zeek IDS rule and pcap testing system☆477Updated 3 months ago
- A (nearly) production ready Dockered MISP☆231Updated last year
- This project is a SIEM with SIRP and Threat Intel, all in one.☆434Updated 5 months ago
- Threat Hunting tool about Sysmon and graphs☆331Updated last year
- Create actionable data from your Vulnerability Scans☆1,379Updated 2 years ago
- Documentation of Cortex☆174Updated last year
- A set of Zeek scripts to detect ATT&CK techniques.☆587Updated 10 months ago
- Actionable analytics designed to combat threats☆982Updated 2 years ago
- Zeek-Formatted Threat Intelligence Feeds☆361Updated this week
- A live dashboard for a real-time overview of threat intelligence from MISP instances☆202Updated last year
- A curated list of awesome things related to TheHive & Cortex☆178Updated 3 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆149Updated last month
- Cortex Analyzers Repository☆458Updated this week
- SIEM Tactics, Techiques, and Procedures☆624Updated this week
- Automated Use Case Testing☆167Updated 7 years ago
- Extract and aggregate threat intelligence.☆862Updated last year
- Detecting ATT&CK techniques & tactics for Linux☆258Updated 4 years ago
- PatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform☆248Updated this week
- MISP trainings, threat intel and information sharing training materials with source code☆407Updated this week
- Suricata rules for network anomaly detection☆160Updated 2 weeks ago
- Python Script to access ATT&CK content available in STIX via a public TAXII server☆565Updated 4 months ago
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,156Updated last year
- Python API Client for TheHive☆224Updated 3 weeks ago
- Elemental - An ATT&CK Threat Library☆318Updated 2 years ago
- Suricata IDS/IPS log analytics using the Elastic Stack.☆238Updated 3 years ago
- PCAP Samples for Different Post Exploitation Techniques☆356Updated 4 years ago