fireeye / HXTool
HXTool is an extended user interface for the FireEye HX Endpoint product. HXTool can be installed on a dedicated server or on your physical workstation. HXTool provides additional features and capabilities over the standard FireEye HX web user interface. HXTool uses the fully documented REST API that comes with the FireEye HX for communication w…
☆79Updated 9 months ago
Alternatives and similar repositories for HXTool:
Users that are interested in HXTool are comparing it to the libraries listed below
- Collection of useful, up to date, Carbon Black Response Queries☆83Updated 4 years ago
- Script for parsing Symantec Endpoint Protection logs, VBNs, and ccSubSDK database.☆64Updated 2 years ago
- ☆87Updated last year
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆53Updated 2 years ago
- ☆68Updated last month
- Collection of walkthroughs on various threat hunting techniques☆75Updated 4 years ago
- Random hunting ordiented yara rules☆95Updated 2 years ago
- A repo to document API functions mapped to security events across diverse platforms☆75Updated 5 years ago
- Blueteam operational triage registry hunting/forensic tool.☆145Updated last year
- Sigma Detection Rule Repository☆87Updated 4 years ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆114Updated last year
- ☆49Updated last year
- Automagically extract forensic timeline from volatile memory dump☆130Updated 11 months ago
- ATT&CK Remote Threat Hunting Incident Response☆200Updated 4 months ago
- ☆116Updated last year
- Useful access control entries (ACE) on system access control list (SACL) of securable objects to find potential adversarial activity☆90Updated 3 years ago
- ☆34Updated 5 months ago
- Active Directory Purple Team Playbook☆108Updated last year
- ☆77Updated 5 years ago
- Detection Ideas & Rules repository.☆179Updated 3 years ago
- Digital Forensics Artifacts Knowledge Base☆81Updated 11 months ago
- Stand-alone parser for User Access Logging from Server 2012 and newer systems☆73Updated last year
- My conference presentations☆66Updated last year
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated 3 weeks ago
- Invoke-LiveResponse☆147Updated 3 years ago
- A Splunk App containing Sigma detection rules, which can be updated from a Git repository.☆108Updated 5 years ago
- Repository with Sample threat hunting notebooks on Security Event Log Data Sources☆63Updated 2 years ago
- attack2jira automates the process of standing up a Jira environment that can be used to track and measure ATT&CK coverage☆112Updated 2 years ago
- ☆6Updated 5 months ago
- A PowerShell incident response script for quick triage☆80Updated 2 years ago