logrhythm / EZ-CloudLinks
OC Admin (Formerly EZ-Cloud) - the Open Collector Admin and On-Boarder for Core SIEM
☆12Updated last year
Alternatives and similar repositories for EZ-Cloud
Users that are interested in EZ-Cloud are comparing it to the libraries listed below
Sorting:
- LogRhythm PowerShell Toolkit☆51Updated 3 weeks ago
- Community content for LogRhythm Axon. Includes Dashboards, searches, analytics rules, processing policies and more.☆10Updated last year
- A repository for using windows event forwarding for incident detection and response☆1,279Updated last year
- A forensics tool to convert the data in the Windows srum (System Resource Usage Monitor) database to an xlsx spreadsheet.☆706Updated 2 months ago
- Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsac…☆875Updated 4 years ago
- The CrowdStrike Falcon SDK for Python☆426Updated last week
- PowerShell for CrowdStrike's OAuth2 APIs☆427Updated this week
- Windows Event Forwarding subscriptions, configuration files and scripts that assist with implementing ACSC's protect publication, Technic…☆224Updated 6 months ago
- Phantom Community Playbooks☆508Updated 2 weeks ago
- CyLR - Live Response Collection Tool☆684Updated 3 years ago
- Incident Response Hierarchy of Needs☆463Updated 2 years ago
- This repository contains Community and Field contributed content for LogScale☆255Updated 2 weeks ago
- A framework for developing alerting and detection strategies for incident response.☆779Updated 3 years ago
- ☆28Updated 5 years ago
- Splunk Content Control Tool☆114Updated last week
- Splunk code (SPL) for serious threat hunters and detection engineers.☆287Updated last year
- A set of Zeek scripts to detect ATT&CK techniques.☆599Updated last year
- Useful network monitoring, analysis, and active response tools used or mentioned in the SANS SEC503 course (https://www.sans.org/course/i…☆233Updated 7 months ago
- Contains Logstash related content including tons of Logstash configurations☆254Updated 3 years ago
- Real-time Response scripts and schema☆115Updated last year
- Documentation of TheHive☆398Updated last year
- Main MineMeld documentation repo☆378Updated 7 years ago
- Repository of SentinelOne Deep Visibility queries.☆129Updated 4 years ago
- ☆43Updated 3 months ago
- A Powershell incident response framework☆1,605Updated 2 years ago
- Scripts that cover the basics of interacting with the AMP for Endpoints API☆17Updated 6 years ago
- Configuration files for the SOF-ELK VM☆1,628Updated this week
- Mark Baggett's (@MarkBaggett - GSE #15, SANS SEC573 Author) tool for detecting randomness using NLP techniques rather than pure entropy c…☆129Updated 2 years ago
- Splunk Boss of the SOC version 2 dataset.☆387Updated 2 years ago
- Splunk Boss of the SOC version 3 dataset.☆359Updated 5 years ago