juaromu / wazuh
☆18Updated 3 years ago
Related projects ⓘ
Alternatives and complementary repositories for wazuh
- ☆15Updated 3 years ago
- Repo for Automations and other solutions for Elastic SIEM/Security.☆18Updated 3 years ago
- Sysmon and wazuh integration with Sigma sysmon rules [updated]☆61Updated 3 years ago
- Personal scripts☆12Updated 2 months ago
- A MITRE ATT&CK Lookup Tool☆43Updated 6 months ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆50Updated 2 years ago
- An experimental Velociraptor implementation using cloud infrastructure☆21Updated last week
- ☆15Updated last year
- Collection of Dashboards for Threat Hunting and more!☆59Updated 4 years ago
- Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents☆38Updated 6 months ago
- Sigma detection rules for hunting with the threathunting-keywords project☆47Updated 2 weeks ago
- Automatic detection engineering technical state compliance☆50Updated 4 months ago
- Library of threat hunts to get any user started!☆40Updated 4 years ago
- Tools for Wazuh by Juan C. Tello☆14Updated 2 years ago
- Workflows for Shuffle☆20Updated 2 years ago
- Sharing Threat Hunting runbooks☆24Updated 5 years ago
- MITRE Engage™ is a framework for conducting Denial, Deception, and Adversary Engagements.☆60Updated 7 months ago
- A collection of Sigma rules organized by MITRE ATT&CK technique☆16Updated 3 years ago
- Repository for SPEED SIEM Use Case Framework☆52Updated 4 years ago
- ☆47Updated this week
- Repo of python/bash scripts for identifying IoC's in threat feed and other online tools☆26Updated 4 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆67Updated last year
- A collection of dashboards, templates, API's and Power BI code for vulnerability management and analysis☆13Updated last week
- A Sigma to Wazuh / OSSEC converter including a generated Windows Sysmon ruleset☆33Updated 4 years ago
- Incident Response Report Using GitHub-Sphinx☆19Updated 5 years ago
- IOCPARSER.COM is a Fast and Reliable service that enables you to extract IOCs and intelligence from different data sources.☆34Updated 2 years ago
- Incident Response Network Tools☆23Updated 3 years ago
- Domain Connectivity Analysis Tools to analyze aggregate connectivity patterns across a set of domains during security investigations☆43Updated 3 years ago
- Intelligence around common attacker behaviors (MITRE ATT&CK TTPs), in the form of ATT&CK Navigator "layer" json files.☆34Updated 2 years ago