martinsohn / CIS-Controls
☆14Updated 2 years ago
Alternatives and similar repositories for CIS-Controls:
Users that are interested in CIS-Controls are comparing it to the libraries listed below
- The Measure, Maximize, and Mature Threat-Informed Defense (M3TID) project defines what Threat-Informed Defense (TID) is and the key activ…☆14Updated last week
- ☆46Updated 2 weeks ago
- Open Threat-Informed Detection Engineering☆37Updated last month
- Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents☆38Updated 9 months ago
- Workflows for Shuffle☆21Updated 2 years ago
- ATT&CK Sync is a Center for Threat-Informed Defense project that aims to improve the ability for organizations to consume MITRE ATT&CK® v…☆18Updated 2 months ago
- The ultimate solution for remotely deploying Crowdstrike sensors quickly and discreetly on any other EDR platform.☆22Updated 5 months ago
- Repository for SPEED SIEM Use Case Framework☆53Updated 4 years ago
- Cloud Analytics helps defenders detect attacks to their cloud infrastructure by developing behavioral analytics for cloud platforms as we…☆52Updated last year
- Repo for Automations and other solutions for Elastic SIEM/Security.☆18Updated 3 years ago
- A tool that allows you to document and assess any security automation in your SOC☆45Updated 3 months ago
- Virtual Security Operations Center☆50Updated last year
- CloudScraper: Tool to enumerate targets in search of cloud resources. S3 Buckets, Azure Blobs, Digital Ocean Storage Space.☆30Updated 2 years ago
- A tool to modify timestamps in a packet capture to a user selected date☆31Updated 3 years ago
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆65Updated 9 months ago
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆19Updated last year
- Repo for Cybercloud Tutorials hosted at cybercloud.guru☆2Updated 5 months ago
- Intelligence around common attacker behaviors (MITRE ATT&CK TTPs), in the form of ATT&CK Navigator "layer" json files.☆34Updated 2 years ago
- Azure function to insert MISP data in to Azure Sentinel☆31Updated 2 years ago
- ☆28Updated 4 years ago
- Presentations☆17Updated 2 years ago
- gundog - guided hunting in Microsoft Defender☆52Updated 3 years ago
- Incident Response Playbooks☆14Updated 5 years ago
- ☆38Updated 9 months ago
- Ingesting Shodan Monitor Alerts to Microsoft Sentinel☆34Updated last year
- Sigma detection rules for hunting with the threathunting-keywords project☆53Updated 2 weeks ago
- ☆18Updated 3 years ago
- A preconfigured Windows-based system designed for rapid forensic investigations in both Azure and AWS.☆38Updated 10 months ago
- ☆37Updated 2 months ago
- An example of how to deploy a Detection as Code pipeline using Sigma Rules, Sigmac, Gitlab CI, and Splunk.☆51Updated 2 years ago