google / osdfir-infrastructure
Helm charts for running open source digital forensic tools in Kubernetes
☆77Updated 3 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for osdfir-infrastructure
- The Sigma command line interface based on pySigma☆136Updated 3 months ago
- Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indi…☆98Updated last month
- ☆83Updated 3 months ago
- An application allowing users to explore, create, annotate, and share extensions of the MITRE ATT&CK® knowledge base. This repository con…☆42Updated 2 weeks ago
- Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help det…☆45Updated 5 months ago
- Anvilogic Forge☆86Updated last week
- LOKI2 - Simple IOC and YARA Scanner☆80Updated 3 months ago
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆66Updated last week
- A tool that allows you to document and assess any security automation in your SOC☆41Updated 3 weeks ago
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆97Updated this week
- ☆67Updated 8 months ago
- pocket guide for core detection engineering concepts☆27Updated last year
- ForgeArmory provides TTPs that can be used with the TTPForge (https://github.com/facebookincubator/ttpforge).☆93Updated 2 months ago
- Remote access and Antivirus Logging Database☆41Updated 6 months ago
- This repository contains helper scripts and custom configs to get the best out of Google's Timesketch project.☆94Updated last year
- ☆37Updated 2 months ago
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆76Updated last week
- Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )☆157Updated 2 months ago
- Simple Workspace Attack Tool (SWAT) is a tool for simulating malicious behavior against Google Workspace in reference to the MITRE ATT&CK…☆161Updated last month
- Import CrowdStrike Threat Intelligence into your instance of MISP☆42Updated last month
- Automated YARA Rule Standardization and Quality Assurance Tool☆166Updated this week
- BlackBerry Threat Research & Intelligence☆93Updated last year
- MISP-STIX-Converter - Python library to handle the conversion between MISP and STIX formats☆50Updated this week
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆27Updated last month
- The core backend server handling API requests and task management☆31Updated 2 weeks ago
- Leveraging MISP indicators via a pDNS-based infrastructure as a poor man’s SOC.☆49Updated last month
- Sigma rule specification☆111Updated 2 weeks ago
- Rules generated from our investigations.☆189Updated 3 weeks ago
- Public script from SANS FOR509 Enterprise Cloud Incident Response☆179Updated 2 months ago
- Cisco Orbital - Osquery queries by Talos☆123Updated 2 months ago