humpalum / vscode-sigma
☆16Updated last month
Related projects ⓘ
Alternatives and complementary repositories for vscode-sigma
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆68Updated last year
- The core backend server handling API requests and task management☆31Updated 2 weeks ago
- Jupyter Notebooks for Cyber Threat Intelligence☆35Updated last year
- ☆31Updated last month
- USN Journal full path builder☆36Updated 2 months ago
- Collection of scripts provided for public use☆31Updated last week
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆35Updated 11 months ago
- 100 Days of YARA to be updated with rules & ideas as the year progresses☆56Updated last year
- ShellSweeping the evil.☆52Updated 5 months ago
- Remote access and Antivirus Logging Database☆41Updated 6 months ago
- Scripts to integrate DFIR-IRIS, MISP and TimeSketch☆31Updated 2 years ago
- A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.☆39Updated 2 years ago
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆49Updated last year
- YARA rule analyzer to improve rule quality and performance☆93Updated 11 months ago
- Library of threat hunts to get any user started!☆40Updated 4 years ago
- Forensic Artifact Collection Tool Matrix☆75Updated last week
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆27Updated last month
- A tool to support the reporting of Authenticode Certificates by reducing the effort on individuals to report.☆27Updated last week
- This repository contains sample log data that were collected after running adversary simulations in Microsoft 365☆20Updated last month
- Sigma detection rules for hunting with the threathunting-keywords project☆47Updated 2 weeks ago
- Logbook for Digital Forensics and Incident Response☆49Updated 4 months ago
- Powershell sandboxing utility☆17Updated 3 weeks ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆23Updated 3 years ago
- ☆1Updated 3 weeks ago
- A pySigma wrapper to manage detection rules.☆29Updated last week
- ☆19Updated last year
- Azure function to insert MISP data in to Azure Sentinel☆30Updated 2 years ago
- Offensive Research Guide to Help Defense Improve Detection☆29Updated last year
- Indicators of compromise from to analysis and research by Nextron Threat Research team☆10Updated last month
- A pySigma wrapper and langchain toolkit for automatic rule creation/translation☆66Updated last week