google / mandiant-ti-clientLinks
☆18Updated last year
Alternatives and similar repositories for mandiant-ti-client
Users that are interested in mandiant-ti-client are comparing it to the libraries listed below
Sorting:
- LOKI2 - Simple IOC and YARA Scanner☆102Updated 2 months ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆84Updated 3 months ago
- A home for detection content developed by the delivr.to team☆70Updated 3 weeks ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆80Updated 3 months ago
- yara detection rules for hunting with the threathunting-keywords project☆127Updated 3 months ago
- LOLESXi is a curated compilation of binaries/scripts available in VMware ESXi that are were used to by adversaries in their intrusions. T…☆132Updated 7 months ago
- ☆121Updated 3 months ago
- Rapid7 Labs operates as the division of Rapid7 focused on threat research. It is renowned for providing comprehensive threat intelligence…☆71Updated 2 months ago
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆116Updated 11 months ago
- Assortment of scripts and tools for our Blackhat EU 2024 talk☆97Updated 6 months ago
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- A pySigma wrapper to manage detection rules.☆41Updated last week
- OSSEM Data Dictionaries☆62Updated 7 months ago
- Yara Rules for Modern Malware☆79Updated last year
- The Sigma command line interface based on pySigma☆158Updated this week
- pySigma Elasticsearch backend☆54Updated this week
- The core backend server handling API requests and task management☆46Updated this week
- YARA rule analyzer to improve rule quality and performance☆103Updated 4 months ago
- This repository is meant to catalog network and host artifacts associated with various EDR products "shell" and response functionalities.☆91Updated last year
- Active C&C Detector☆156Updated last year
- A Dissect module implementing a parser for Microsofts Extensible Storage Engine Database (ESEDB), used for example in Active Directory, E…☆21Updated last month
- ☆16Updated 5 months ago
- Repository that contains a set of purposefully erroneous Yara rules.☆58Updated last month
- HTTP Headers Hashing (HHHash) is a technique used to create a fingerprint of an HTTP server based on the headers it returns.☆77Updated 2 years ago
- Helm charts for running open source digital forensic tools in Kubernetes☆116Updated 2 weeks ago
- BlackBerry Threat Research & Intelligence☆98Updated last year
- ShellSweeping the evil.☆53Updated last year
- An extension of the sigma standard to include security metrics.☆15Updated 2 years ago
- Python API for interacting with sigma rules.☆54Updated 3 years ago
- Validates Sigma rules using the JSON schema☆16Updated last year