elastic / security-docs
Elastic Security Documentation
☆86Updated this week
Alternatives and similar repositories for security-docs:
Users that are interested in security-docs are comparing it to the libraries listed below
- elastic-package - Command line tool for developing Elastic Integrations☆56Updated this week
- Repo for developing the endpoint package☆24Updated this week
- Elastic Agent - single, unified way to add monitoring for logs, metrics, and other types of data to a host.☆163Updated this week
- SIEGMA - Transform Sigma rules into SIEM consumables☆149Updated 2 weeks ago
- EPR package specifications☆19Updated this week
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated last month
- Command line tool used for generating events corpus dynamically given a specific integration☆23Updated last month
- ☆270Updated this week
- SIEM Logstash parsing for more than hundred technologies☆183Updated this week
- Elastic Observability Documentation☆37Updated this week
- OCA-wide documentation shared by all sub-projects and repositories☆33Updated 4 months ago
- Cisco Orbital - Osquery queries by Talos☆130Updated 7 months ago
- SIGMA UI is a free open-source application based on the Elastic stack and Sigma Converter (sigmac)☆186Updated 3 years ago
- The Fleet server allows managing a fleet of Elastic Agents.☆92Updated this week
- Wazuh - Splunk App☆52Updated 6 months ago
- ☆34Updated last week
- Package storage for packages served through the package registry service☆10Updated 2 years ago
- An application allowing users to explore, create, annotate, and share extensions of the MITRE ATT&CK® knowledge base. This repository con…☆44Updated this week
- ☆48Updated this week
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
- OSSEM Common Data Model☆55Updated 2 years ago
- Security Analytics enables users for detecting security threats on their security event log data. It will also allow them to modify/tailo…☆79Updated last week
- Sigma rules from Joe Security☆207Updated 4 months ago
- Parse wazuh[HIDS] alerts into ECS mapping using Filebeat☆27Updated 4 years ago
- Open source endpoint agent providing host information to Zeek. [v2]☆77Updated 5 months ago
- OpenCTI Docker deployment helpers☆178Updated last week
- A curated list of awesome things related to TheHive & Cortex☆177Updated 3 years ago
- The Sigma command line interface based on pySigma☆147Updated last month
- Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.☆311Updated 6 months ago
- An opensource sigma conversion tool built using pysigma☆121Updated 3 months ago