elastic / detection-rules-explorerLinks
☆20Updated this week
Alternatives and similar repositories for detection-rules-explorer
Users that are interested in detection-rules-explorer are comparing it to the libraries listed below
Sorting:
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆92Updated last month
- ☆42Updated last month
- The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects…☆43Updated 4 years ago
- Slides of my public talks☆56Updated last year
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆84Updated 2 months ago
- Mapping of open-source detection rules and atomic tests.☆174Updated 6 months ago
- Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations☆93Updated last year
- Full of public notes and Utilities☆127Updated 6 months ago
- pySigma Elasticsearch backend☆54Updated this week
- The Eventlog Compendium is the go-to resource for understanding Windows Event Logs.☆48Updated 3 months ago
- The Github project for The Defender's Guide by Luke Paine and Jonathan Johnson☆154Updated 2 years ago
- OSSEM Data Dictionaries☆62Updated 6 months ago
- Provides an advanced baseline to implement a secure Windows auditing strategy on Windows OS.☆55Updated 2 months ago
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆47Updated 3 months ago
- A collection of various SIEM rules relating to malware family groups.☆68Updated last year
- Hunting Queries for Defender ATP☆82Updated 4 months ago
- ☆94Updated last week
- A repository to share publicly available Velociraptor detection content☆186Updated this week
- ☆101Updated last month
- Online resources related to Detection Engineering. Detection rules, detection logic, attack samples, detection tests and emulation tools…☆112Updated last month
- Dettectinator - The Python library to your DeTT&CT YAML files.☆115Updated 4 months ago
- Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.☆134Updated 2 years ago
- REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.☆37Updated 6 months ago
- MISP to Sentinel integration☆71Updated 3 weeks ago
- Sigma rules to share with the community☆121Updated 6 months ago
- ☆73Updated 9 months ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆66Updated last year
- yara detection rules for hunting with the threathunting-keywords project☆126Updated 3 months ago
- Elastic Security Labs releases☆79Updated last month
- Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques☆136Updated last year