jmpsec / osctrl
Fast and efficient osquery management
☆425Updated this week
Alternatives and similar repositories for osctrl:
Users that are interested in osctrl are comparing it to the libraries listed below
- A repository for using osquery for incident detection and response☆842Updated 2 years ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆790Updated last year
- osquery extensions by Trail of Bits☆263Updated last year
- Osquery launcher, autoupdater, and packager☆517Updated this week
- Production-ready detection & response queries for osquery☆554Updated this week
- Transform Linux Audit logs for SIEM usage☆754Updated last week
- Manage, monitor and improve your cyber security posture.☆89Updated last year
- Security event correlation engine for ELK stack☆435Updated 8 months ago
- Documentation of Cortex☆174Updated last year
- an osquery fleet manager☆618Updated 2 years ago
- Real-time, container-based file scanning at enterprise scale☆913Updated this week
- ⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident…☆383Updated last week
- Osquery Resources☆60Updated 5 years ago
- A Linux Auditd rule set mapped to MITRE's Attack Framework☆786Updated 4 years ago
- PatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform☆247Updated last week
- Cisco Orbital - Osquery queries by Talos☆130Updated 7 months ago
- Built-in Panther detection rules and policies☆369Updated this week
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆176Updated 6 months ago
- 🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.☆262Updated 2 years ago
- PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform☆630Updated 2 weeks ago
- A standard for reducing log volume without sacrificing analytical capability☆203Updated last month
- A framework for orchestrating forensic collection, processing and data export☆307Updated this week
- Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search☆449Updated 2 weeks ago
- Automated deployment scripts for the RockNSM network hunting distribution.☆451Updated last year
- Zeek-Formatted Threat Intelligence Feeds☆356Updated this week
- DFIRTrack - The Incident Response Tracking Application☆492Updated 6 months ago
- Zeek IDS Dockerfile☆101Updated 2 years ago
- MISP Docker (XME edition)☆283Updated last year
- Documentation of TheHive☆396Updated last year
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆390Updated this week