juaromu / wazuh
☆18Updated 3 years ago
Alternatives and similar repositories for wazuh:
Users that are interested in wazuh are comparing it to the libraries listed below
- ☆16Updated 3 years ago
- Repo for Automations and other solutions for Elastic SIEM/Security.☆18Updated 3 years ago
- Open Threat-Informed Detection Engineering☆28Updated last week
- Log aggregation, analysis, alerting and correlation for Windows, Syslog and text based logs.☆24Updated 8 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆23Updated this week
- Sigma detection rules for hunting with the threathunting-keywords project☆51Updated last month
- Personal scripts☆12Updated 4 months ago
- ☆49Updated this week
- Library of threat hunts to get any user started!☆41Updated 4 years ago
- IOCPARSER.COM is a Fast and Reliable service that enables you to extract IOCs and intelligence from different data sources.☆34Updated 2 years ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆50Updated 2 years ago
- Sysmon and wazuh integration with Sigma sysmon rules [updated]☆62Updated 3 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆23Updated 3 years ago
- ☆15Updated last year
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆15Updated last year
- Workflows for Shuffle☆21Updated 2 years ago
- SkillAegis is a platform to design, run, and monitor exercise scenarios, enhancing skills in applications like MISP and training users in…☆22Updated last month
- Run Velociraptor on Security Onion☆37Updated 2 years ago
- TheHiveIRPlaybook is a collection of TheHive case templates used for Incident Response☆13Updated 4 years ago
- A home for detection content developed by the delivr.to team☆63Updated last month
- Automatic detection engineering technical state compliance☆53Updated 6 months ago
- Script to test NetSec capabilities.☆21Updated last year
- This script is to build Wazuh 4.3 environment☆13Updated 2 years ago
- Intelligence around common attacker behaviors (MITRE ATT&CK TTPs), in the form of ATT&CK Navigator "layer" json files.☆34Updated 2 years ago
- Repository for SPEED SIEM Use Case Framework☆52Updated 4 years ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆59Updated 8 months ago
- Open-source Fabric templates for cybersecurity and compliance☆15Updated this week
- MITRE Engage™ is a framework for conducting Denial, Deception, and Adversary Engagements.☆61Updated 9 months ago
- Tools for Wazuh by Juan C. Tello☆14Updated 3 years ago