elastic / endpoint
☆33Updated 10 months ago
Alternatives and similar repositories for endpoint:
Users that are interested in endpoint are comparing it to the libraries listed below
- OSSEM Data Dictionaries☆59Updated last week
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆63Updated 2 years ago
- ☆48Updated last week
- A CALDERA plugin☆74Updated 2 months ago
- pySigma Splunk backend☆35Updated last week
- ☆64Updated last week
- Dettectinator - The Python library to your DeTT&CT YAML files.☆107Updated 2 weeks ago
- OSSEM Common Data Model☆55Updated 2 years ago
- ☆18Updated this week
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆137Updated this week
- A repository of my own Sigma detection rules.☆157Updated 4 months ago
- This will be a repository of SentinelOne Deep Visibility queries both the Standard Queries and the Power Queries. Most of these queries w…☆25Updated 3 months ago
- Open Threat-Informed Detection Engineering☆32Updated 2 weeks ago
- Import CrowdStrike Threat Intelligence into your instance of MISP☆42Updated 3 months ago
- Full of public notes and Utilities☆95Updated 2 months ago
- Intel Retrieval Augmented Generation (RAG) Utilities☆90Updated last year
- This CALDERA Plugin converts Adversary Emulation Plans from the Center for Threat Informed Defense☆29Updated 11 months ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆75Updated last year
- Collects a listing of MITRE ATT&CK Techniques, then discovers Splunk ESCU detections for each technique☆65Updated 10 months ago
- Anything Sysmon related from the MSTIC R&D team☆148Updated 7 months ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- Slides of my public talks☆49Updated last year
- ☆86Updated 5 months ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆73Updated last week
- Mapping your datasources and detections to the MITRE ATT&CK Navigator framework.☆57Updated 4 years ago
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆36Updated last year
- pySigma Elasticsearch backend☆49Updated this week
- This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports☆66Updated 2 months ago
- MITRE Engage™ is a framework for conducting Denial, Deception, and Adversary Engagements.☆62Updated 9 months ago
- ShellSweeping the evil.☆52Updated 7 months ago