jmpsec / osctrl
Fast and efficient osquery management
☆437Updated this week
Alternatives and similar repositories for osctrl:
Users that are interested in osctrl are comparing it to the libraries listed below
- A repository for using osquery for incident detection and response☆843Updated 2 years ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆790Updated last year
- Osquery launcher, autoupdater, and packager☆520Updated this week
- Transform Linux Audit logs for SIEM usage☆759Updated 2 weeks ago
- Manage, monitor and improve your cyber security posture.☆90Updated last year
- osquery extensions by Trail of Bits☆264Updated 2 years ago
- ⚡️ Catalyst is a self-hosted, open source incident response platform and ticket system that helps to automate alert handling and incident…☆388Updated this week
- Production-ready detection & response queries for osquery☆561Updated 3 weeks ago
- Real-time, container-based file scanning at enterprise scale☆920Updated this week
- an osquery fleet manager☆618Updated 2 years ago
- Osquery Resources☆60Updated 5 years ago
- Security event correlation engine for ELK stack☆438Updated 9 months ago
- 🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.☆261Updated 2 years ago
- A standard for reducing log volume without sacrificing analytical capability☆203Updated last month
- Open source endpoint agent providing host information to Zeek. [v2]☆80Updated 5 months ago
- A framework for orchestrating forensic collection, processing and data export☆310Updated last week
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆177Updated 6 months ago
- Graph platform for Detection and Response☆691Updated 2 years ago
- simple YARA-based IOC scanner☆168Updated 2 months ago
- A utility to safely generate malicious network traffic patterns and evaluate controls.☆1,301Updated last year
- Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search☆453Updated last week
- Documentation of Cortex☆174Updated last year
- Cisco Orbital - Osquery queries by Talos☆132Updated 7 months ago
- DFIRTrack - The Incident Response Tracking Application☆498Updated 7 months ago
- PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform☆631Updated last week
- PatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform☆247Updated 2 weeks ago
- Jimi is an automation first no-code platform designed and developed originally for Security Orchestration and Response. Since its launch …☆165Updated 9 months ago
- A Linux Auditd rule set mapped to MITRE's Attack Framework☆787Updated 4 years ago
- The tool for updating your Suricata rules.☆270Updated last week
- Automated Use Case Testing☆167Updated 6 years ago