michaelpeacock / kafka-sigma-streamsLinks
☆19Updated 3 years ago
Alternatives and similar repositories for kafka-sigma-streams
Users that are interested in kafka-sigma-streams are comparing it to the libraries listed below
Sorting:
- ☆42Updated 2 years ago
 - Analyze Zeek IDS data with ksqlDB running on Confluent Platform via Docker on your laptop. Or spin up an arbitrary number of AWS hosts, …☆11Updated 4 years ago
 - Elastic Beat for fetching and shipping Office 365 audit events☆68Updated 5 years ago
 - PowerShell - Endpoint Analysis Solution Your Windows Intranet Needs☆48Updated 10 months ago
 - The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects…☆44Updated 4 years ago
 - Knowing which rule should trigger according to the redcannary test☆11Updated 11 months ago
 - This package allows the use of a custom Elastalert Alert which creates alerts with observables in TheHive using TheHive4Py.☆27Updated 4 years ago
 - Pushes Sysmon Configs☆88Updated 4 years ago
 - This repository was created to aid in the deployment/maintenance of the Sysmon service on a large number of computers.☆83Updated 2 years ago
 - Kerberos Haters Guide to Zeek Threat Hunting☆32Updated 4 years ago
 - Automated detection rule analysis utility☆29Updated 3 years ago
 - Converts Sigma detection rules to a Splunk alert configuration.☆113Updated 5 years ago
 - Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆53Updated last month
 - Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆93Updated 4 months ago
 - A tool to modify timestamps in a packet capture to a user selected date☆31Updated 4 years ago
 - Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆38Updated last year
 - Repository for SPEED SIEM Use Case Framework☆56Updated 5 years ago
 - A Sigma to Wazuh / OSSEC converter including a generated Windows Sysmon ruleset☆35Updated 5 years ago
 - Provides detection capabilities and log conversion to evtx or syslog capabilities☆54Updated 3 years ago
 - The CyberCX Digger project is designed to help Australian organisations determine if they have been impacted by certain high profile cybe…☆45Updated 5 years ago
 - A PowerShell incident response script for quick triage☆81Updated 3 years ago
 - RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆37Updated 3 years ago
 - Deploy and maintain Symon through the Splunk Deployment Sever☆30Updated 5 years ago
 - A collection of Cortex Analyzers and Responders for TheHive/Cortex☆13Updated 5 years ago
 - SOC Workflow App helps Security Analysts and Threat Hunters explore suspicious events, look into raw events arriving at the Elastic Stack…☆93Updated 3 years ago
 - A collection of useful PowerShell tools to collect, organize, and visualize Sysmon event data☆39Updated 5 years ago
 - Synthetic Adversarial Log Objects: A Framework for synthentic log generation☆85Updated last year
 - A Splunk technology add-on for osquery☆14Updated last month
 - Azure Sentinel Template parser☆16Updated 5 years ago
 - Web app that provides basic navigation and annotation of ATT&CK matrices☆17Updated 4 years ago