guardicode / osqueryLinks
Guardicore osqueries collection for asset information, TH and compliance.
☆14Updated 3 years ago
Alternatives and similar repositories for osquery
Users that are interested in osquery are comparing it to the libraries listed below
Sorting:
- ☆87Updated 8 months ago
- Run Velociraptor on Security Onion☆40Updated 3 years ago
- A curated list of awesome things related to TheHive & Cortex☆182Updated 4 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆78Updated 3 weeks ago
- Sysmon and wazuh integration with Sigma sysmon rules [updated]☆70Updated 4 years ago
- ☆43Updated 2 years ago
- Run zeek with zeekctl in docker☆55Updated last year
- Controls Assessment Specification☆70Updated 7 months ago
- This repository is a comprehensive collection of resources, documentation, apps, and add-ons related to Splunk, a powerful data analytics…☆23Updated last week
- The Infosec Community Definitive Guide to Jupyter Notebooks☆126Updated 5 years ago
- Security Onion + Automation + Response Lab including n8n and Velociraptor☆112Updated 3 years ago
- A tool that allows you to document and assess any security automation in your SOC☆47Updated last year
- Implementing the CIS Critical Controls (almost) for Free☆86Updated 3 years ago
- CrowdStrike's Open Source Policy & Contribution Guide☆45Updated last month
- Collection of Dashboards for Threat Hunting and more!☆70Updated 5 years ago
- A list of Splunk queries that I've collected and used over time.☆87Updated 5 years ago
- Ansible playbook for installing MineMeld on Linux☆48Updated 4 years ago
- ☆45Updated 3 years ago
- Docker image for MISP☆135Updated 2 months ago
- Elastic TIP is a python tool which automates the process of aggregating Threat Intelligence and ingesting the intelligence into a common …☆28Updated last year
- ☆55Updated 4 years ago
- This TA takes Suricata5 data from your port mirrored Suricata server and makes it readable within Splunk. See Cheatsheets on how to setup…☆15Updated 5 years ago
- Leverage Sophos Central API☆30Updated 2 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆157Updated 7 months ago
- Home for Splunk security datasets.☆125Updated 5 years ago
- Tool to extract Sessions, MessageID(s) and find the emails belonging to MessageID(s). This script utilizes the MailItemsAccessed features…☆41Updated 5 years ago
- Passive service locator, a python sniffer that identifies servers, clients, names and much more☆256Updated 2 years ago
- Repository for SPEED SIEM Use Case Framework☆56Updated 5 years ago
- Standard-Format Threat Intelligence Feeds☆124Updated this week
- A list of resources to build a information security team.☆13Updated 4 years ago