grapl-security / grapl
Graph platform for Detection and Response
☆690Updated 2 years ago
Alternatives and similar repositories for grapl:
Users that are interested in grapl are comparing it to the libraries listed below
- A Linux Auditd rule set mapped to MITRE's Attack Framework☆786Updated 4 years ago
- A repository for using osquery for incident detection and response☆842Updated 2 years ago
- Fast and efficient osquery management☆426Updated this week
- Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.☆1,287Updated 2 years ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆790Updated last year
- (DEPRECATED) Diffy is a triage tool used during cloud-centric security incidents, to help digital forensics and incident response (DFIR)…☆633Updated last year
- A utility to safely generate malicious network traffic patterns and evaluate controls.☆1,295Updated 11 months ago
- Real-time, container-based file scanning at enterprise scale☆913Updated this week
- Chain Reactor is an open source framework for composing executables that simulate adversary behaviors and techniques on Linux endpoints.☆303Updated 4 months ago
- A Python package to interact with the Mitre ATT&CK Framework☆474Updated last year
- An information security preparedness tool to do adversarial simulation.☆1,118Updated 5 years ago
- The main project for the Unfetter-Discover application. This is the project that will hold the configuration files, the docker-compose f…☆412Updated 2 years ago
- HASSH is a network fingerprinting standard which can be used to identify specific Client and Server SSH implementations. The fingerprints…☆538Updated last year
- Actionable analytics designed to combat threats☆982Updated 2 years ago
- Open Source Security Events Metadata (OSSEM)☆1,260Updated 2 years ago
- An analytical framework for network traffic and behavioral analytics☆450Updated 2 years ago
- AVML - Acquire Volatile Memory for Linux☆923Updated last week
- Transform Linux Audit logs for SIEM usage☆754Updated 2 weeks ago
- Tenzir is the data pipeline engine for security teams.☆670Updated this week
- Praetorian's public release of our Metasploit automation of MITRE ATT&CK™ TTPs☆721Updated 5 years ago
- File Scanning Framework☆292Updated 3 years ago
- Incident Response Forensic Framework☆599Updated 5 years ago
- Python Script to access ATT&CK content available in STIX via a public TAXII server☆562Updated 3 months ago
- A framework for developing alerting and detection strategies for incident response.☆726Updated 3 years ago
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,510Updated 8 months ago
- ☆1,068Updated 5 years ago
- DPS' Lightweight Investigation Notebook☆427Updated last year
- Re-play Security Events☆1,629Updated last year
- Security event correlation engine for ELK stack☆435Updated 9 months ago
- The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).☆544Updated last year