ebarti / cortex-xdr-clientLinks
A python-based API client for Cortex XDR API.
☆26Updated 4 months ago
Alternatives and similar repositories for cortex-xdr-client
Users that are interested in cortex-xdr-client are comparing it to the libraries listed below
Sorting:
- Threat Hunting queries for various attacks☆244Updated 3 weeks ago
- ☆553Updated 2 years ago
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆213Updated this week
- Automatically created C2 Feeds☆662Updated this week
- Test the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-Cradle…☆312Updated 4 years ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆612Updated 2 months ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆778Updated this week
- Anything Sysmon related from the MSTIC R&D team☆156Updated last year
- Open Dataset of Cobalt Strike Beacon metadata (2018-2022)☆133Updated 3 years ago
- Sublime rules for email attack detection, prevention, and threat hunting.☆345Updated this week
- Attack Flow helps executives, SOC managers, and defenders easily understand how attackers compose ATT&CK techniques into attacks by devel…☆712Updated 2 months ago
- OSSEM Detection Model☆184Updated 3 years ago
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆411Updated 3 months ago
- Incident Response - Fast suspicious file finder☆249Updated 2 weeks ago
- Automation scripts to deploy Windows Event Forwarding, Sysmon, and custom audit policies in an Active Directory environment.☆489Updated last year
- The principal objective of this project is to develop a knowledge base of the tactics, techniques, and procedures (TTPs) used by insiders…☆148Updated 7 months ago
- Ransomware simulator written in Golang☆470Updated 3 years ago
- Hunting queries and detections☆878Updated 3 months ago
- RdpCacheStitcher is a tool that supports forensic analysts in reconstructing useful images out of RDP cache bitmaps.☆310Updated 2 years ago
- ☆160Updated 2 years ago
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆527Updated this week
- The Sigma command line interface based on pySigma☆176Updated last month
- Evtx to Splunk ingestor☆16Updated 3 years ago
- #ThreatHunting #DFIR #Malware #Detection Mind Maps☆306Updated 4 years ago
- Protect your Domain Controllers by auditing and restricting LDAP requests☆179Updated 8 months ago
- ☆128Updated 2 years ago
- Cobalt Strike Beacon configuration extractor and parser.☆160Updated 3 months ago
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆94Updated 7 months ago
- ATT&CK Evaluations Library☆92Updated 2 weeks ago
- ☆14Updated 3 years ago