This program exports MITRE ATT&CK framework in ELK dashboard
☆80Dec 8, 2022Updated 3 years ago
Alternatives and similar repositories for attack-to-elk
Users that are interested in attack-to-elk are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- OSSEM Modular☆27Jun 29, 2020Updated 6 years ago
- Python libary to normalize Yara signatures☆19Oct 9, 2020Updated 5 years ago
- Code and Slides of my BSides London 2019 presentation about Attacker Emulation using CALDERA☆22Jun 9, 2019Updated 7 years ago
- Kibana app for RedELK☆18Mar 19, 2023Updated 3 years ago
- Table Top Exercise (TTX) for Computer Security Incident Response (CSIRT) teams. The templatized artifacts provided will hopefully help te…☆44Sep 8, 2020Updated 5 years ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Web UI for testing Elastic Beats processors☆18Feb 22, 2026Updated 4 months ago
- A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework☆358Nov 3, 2020Updated 5 years ago
- Python Script to access ATT&CK content available in STIX via a public TAXII server☆571Dec 19, 2025Updated 7 months ago
- ☆10Oct 23, 2024Updated last year
- ☆29Feb 16, 2021Updated 5 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆33Jul 7, 2026Updated last week
- This is a repository from Adam Swan and I's presentation on Windows Logs Zero 2 Hero.☆22Jan 30, 2018Updated 8 years ago
- Script for automating Linux memory capture and analysis☆12May 6, 2020Updated 6 years ago
- This batch script file wants to check your EDR systems detection and response capabilities in a more noisy way!☆12Jul 3, 2020Updated 6 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- Standalone CIRCLean/KittenGroomer code to sanitize emails.☆11Aug 9, 2018Updated 7 years ago
- A curated list of tools, papers and techniques for Windows exploitation and incident response.☆42Apr 10, 2016Updated 10 years ago
- Open-source framework to detect outliers in Elasticsearch events☆204May 22, 2023Updated 3 years ago
- Test Blue Team detections without running any attack.☆272May 2, 2024Updated 2 years ago
- A Splunk App containing Sigma detection rules, which can be updated from a Git repository.☆111Feb 6, 2020Updated 6 years ago
- Top ATT&CK Techniques helps defenders approach the breadth and complexity of MITRE ATT&CK® with a prioritized top 10 list of techniques t…☆127May 28, 2025Updated last year
- ☆24Nov 3, 2019Updated 6 years ago
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,190Jul 26, 2023Updated 2 years ago
- Searches open files shares for password files, database backups, etc. Extend as you see fit☆29Dec 13, 2019Updated 6 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Read only mirror. To contribute or submit issues, please go to the website link --->☆15Jul 25, 2023Updated 2 years ago
- Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK☆1,078Nov 28, 2024Updated last year
- MAL-CL (Malicious Command-Line)☆330Jan 10, 2023Updated 3 years ago
- Collection of malware ioc hashes from blog posts. A Python script is provided to search through it.☆19Sep 10, 2020Updated 5 years ago
- Powerful XML<->JSON JavaScript mapping library.☆16Apr 29, 2026Updated 2 months ago
- Parser for Windows Scheduled Task files.☆13Apr 26, 2023Updated 3 years ago
- Place for resources used during the Mordor Detection hackathon event featuring APT29 ATT&CK evals datasets☆146Oct 12, 2020Updated 5 years ago
- ☆14Mar 5, 2021Updated 5 years ago
- A command-line tool for parsing Windows Event Logs and importing the results into Elasticsearch.☆88Jun 2, 2026Updated last month
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Tool for analysis of Windows Prefetch files☆26Nov 11, 2018Updated 7 years ago
- Scripts to threat optics stack quickly / abbreviated and automated. Run after APT-Lab-Terraform☆13Oct 24, 2020Updated 5 years ago
- Applied Purple Teaming - (ITOCI4hr) - Infrastructure, Threat Optics, and Continuous Improvement - June 6, 2020☆325Jan 22, 2021Updated 5 years ago
- A lightweight Python module to interact with the MITRE ATT&CK® Enterprise dataset. Built for speed with minimal dependencies. Read the do…☆11Nov 24, 2025Updated 7 months ago
- Additional README's for XSOAR and XSOAR related things☆14Oct 4, 2023Updated 2 years ago
- ☆56May 13, 2020Updated 6 years ago
- InSpec profile to validate the secure configuration of Red Hat Enterprise Linux 7, against DISA's Red Hat Enterprise Linux 7 Security Tec…☆15Dec 15, 2025Updated 7 months ago