SOAR Automation with Shuffle, Wazuh & TheHive | This project integrates Shuffle SOAR, Wazuh SIEM, and TheHive to automate security incident response. It enriches alerts using VirusTotal & AbuseIPDB, creates incidents in TheHive, and sends real-time Discord notifications.
☆138Feb 21, 2025Updated last year
Alternatives and similar repositories for SOAR-Flow
Users that are interested in SOAR-Flow are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Security Monitoring using Wazuh, published by Packt☆44Apr 22, 2026Updated 5 months ago
- MCP Server for TheHive☆15Dec 6, 2025Updated 9 months ago
- SysX (RAT or RMM) is for educational or internal demo use only. Do not upload this binary to VirusTotal or other public sandboxes.☆22Sep 2, 2025Updated last year
- AI-Powered Static Application Security Testing (SAST) — written in Go.☆39Mar 19, 2026Updated 6 months ago
- This project automates SOC workflows using Wazuh, Shuffle, and TheHive. It involves setting up a Windows 10 client with Sysmon and Ubuntu…☆50Jun 7, 2024Updated 2 years ago
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- ☆22Apr 10, 2025Updated last year
- ☆18Sep 22, 2025Updated last year
- SIEM, Visibility, and Event-Driven Architecture Curated Solutions. Build a cost-effective threat detection and log management system.☆22Jan 17, 2024Updated 2 years ago
- ☆43Dec 24, 2024Updated last year
- Menu for Thor scanner lite☆20Oct 24, 2025Updated 10 months ago
- AI-Driven Breach and Attack Simulation Tool (Initial Proof of Concept for AI Pentest Copilot)☆28Jan 6, 2025Updated last year
- Linux version of Splunk MCP LLM MCP SIEMulator . A Docker lab integrating Splunk SIEM with Ollama LLM via Model Context Protocol for AI-p…☆19Sep 2, 2026Updated 2 weeks ago
- Turn any blog into structured threat intelligence.☆63Updated this week
- Mapping of open-source detection rules and atomic tests.☆215Jul 15, 2026Updated 2 months ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- If you a security engineer or an aspirant Security professional then Setting up a Wazuh home lab environment is an excellent way for SOC …☆24Mar 27, 2024Updated 2 years ago
- Repo to hold wazuh manager mcp server☆93Apr 15, 2026Updated 5 months ago
- Hands-on projects for beginners to learn and practice Linux forensics and essential cybersecurity skills☆18Jun 29, 2024Updated 2 years ago
- Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.☆247Updated this week
- Awesome List of Enterprise Security Tools' Community Edition☆16Jul 29, 2026Updated last month
- Scripts for importing threat feeds and CTI articles, blogs, and reports into MISP.☆18Jun 28, 2026Updated 2 months ago
- In this projects are custom-decoders and custom-rules for Wazuh by me. Feel free to use it, you can redistribute it and/or modify it unde…☆66Mar 7, 2026Updated 6 months ago
- my MSTICpy practice and custom tools repository☆11Apr 23, 2025Updated last year
- AI-Agentic Threat Intelligence - 39 collectors, 7 AI agents, 3-link proof chain, D1-D5 exposure scoring☆70Mar 16, 2026Updated 6 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- ☆15Jun 4, 2026Updated 3 months ago
- ☆49Jul 9, 2024Updated 2 years ago
- Keylogger for Windows that goes unnoticed by the antivirus☆32Dec 4, 2024Updated last year
- CSF Firewall and AbuseIPDB API integration with specific focus on data privacy and prevention of sensitive data leaked to public AbuseIPD…☆17Mar 20, 2024Updated 2 years ago
- CarbonBlack EDR detection rules and response actions☆73Sep 10, 2024Updated 2 years ago
- EnumDNS is a modular DNS reconnaissance tool capable of resolving hosts from various sources, including wordlists, BloodHound files, and …☆21Aug 10, 2026Updated last month
- DECeption with Evaluative Integrated Validation Engine (DECEIVE): Let an LLM do all the hard honeypot work!☆294Aug 27, 2026Updated 3 weeks ago
- Autonomous AI SOC for Wazuh SIEM — 11 security-expert agents triage, correlate, investigate and plan responses 24/7, every action gated b…☆57Aug 8, 2026Updated last month
- SOCAutomators Substack blog companion — threat research, DBIR analysis, and security operations content☆21Jun 3, 2026Updated 3 months ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- Production-grade MCP server for Wazuh SIEM — 55 security tools for alert triage, threat hunting, vulnerability management, compliance (PC…☆237Updated this week
- Repo of python/bash scripts for identifying IoC's in threat feed and other online tools☆28Jul 27, 2020Updated 6 years ago
- Pentest automation resources for Burp☆15Mar 10, 2024Updated 2 years ago
- ThreatSeeker: Threat Hunting via Windows Event Logs☆124May 16, 2023Updated 3 years ago
- Kubernetes, Clusters and Dockers Enumeration in GCP and AWS environments☆12Nov 23, 2023Updated 2 years ago
- Cybether - A modern, open-source Cybersecurity Governance, Risk, and Compliance (GRC) dashboard☆94Dec 14, 2025Updated 9 months ago