michaelpeacock / kafka-sigma-streams
☆19Updated 2 years ago
Alternatives and similar repositories for kafka-sigma-streams:
Users that are interested in kafka-sigma-streams are comparing it to the libraries listed below
- Analyze Zeek IDS data with ksqlDB running on Confluent Platform via Docker on your laptop. Or spin up an arbitrary number of AWS hosts, …☆11Updated 3 years ago
- Geospatial UDFs for KSQL☆22Updated 3 years ago
- Confluent s2s Demo☆10Updated last year
- ☆41Updated last year
- Sentinel Threat Intelligence Upload Toolkit☆13Updated 8 months ago
- The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects…☆40Updated 4 years ago
- Ansible role for installing Sysmon with popular config files included.☆24Updated 2 years ago
- A collection of Cortex Analyzers and Responders for TheHive/Cortex☆13Updated 5 years ago
- This repository was created to aid in the deployment/maintenance of the Sysmon service on a large number of computers.☆82Updated 2 years ago
- REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.☆32Updated 2 months ago
- Azure Sentinel Template parser☆16Updated 4 years ago
- Web app that provides basic navigation and annotation of ATT&CK matrices☆16Updated 4 years ago
- This hosts all queries created on the LD&R Forum☆11Updated last month
- ☆27Updated 7 months ago
- ☆58Updated last year
- Read only mirror. To contribute or submit issues, please go to the website link --->☆13Updated last year
- A collection of scripts useful in management of Splunk deployment☆20Updated 7 months ago
- Parses the FireEye HX .mans triage collections and sends them to ElasticSearch☆14Updated 2 years ago
- Convert Sigma rules to LogRhythm searches☆20Updated 3 years ago
- Elastic Beat for fetching and shipping Office 365 audit events☆67Updated 4 years ago
- A collection of tips for using MISP.☆74Updated 3 months ago
- Cisco eStreamer client☆24Updated 2 years ago
- Generates a detailed CSV file containing Sigma Rules statistics for each service or category, and each level, offering a holistic view of…☆10Updated last year
- ☆69Updated last year
- BulkStrike enables the usage of CrowdStrike Real Time Response (RTR) to bulk execute commands on multiple machines.☆42Updated 2 years ago
- ☆14Updated 6 months ago
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆18Updated 4 months ago
- RRR (Rapid Response Reporting) is a collection of Incident Response Report objects. They are designed to help incident responders provid…☆37Updated 2 years ago
- Threat Simulator for Enterprise Networks☆14Updated 2 years ago
- Splunk Add on for OPNsense firewall☆1Updated 6 months ago