mikermcneil / fleet-osquery-in-a-box
Simple Docker-based quickstart for osquery, Fleet, and ELK stack
☆62Updated last year
Alternatives and similar repositories for fleet-osquery-in-a-box:
Users that are interested in fleet-osquery-in-a-box are comparing it to the libraries listed below
- ☆15Updated 5 years ago
- Scripts from my book OS X Incident Response Scripting and Analysis -> https://www.amazon.com/dp/012804456X/ref=cm_sw_r_tw_dp_U_x_fQeLAb68…☆49Updated 8 years ago
- Actionable analytics designed to combat threats based on MITRE's ATT&CK.☆22Updated 5 years ago
- ☆34Updated 3 years ago
- Attack Range to test detection against nativel serverless cloud services and environments☆35Updated 3 years ago
- ☆33Updated 2 years ago
- ☆34Updated last year
- misp-cloud - Cloud-ready images of MISP☆72Updated 2 years ago
- Recon Hunt Queries☆76Updated 3 years ago
- Security Monitoring Resolution Categories☆138Updated 3 years ago
- Documentation for ROCK NSM☆24Updated 3 years ago
- Repository containing Jupyter Notebooks for working with OSQuery tables and data☆17Updated 4 years ago
- Automated deployment of MISP and MISP-Dashboard via K8S and AWS☆19Updated 5 years ago
- This repository was created to aid in the deployment/maintenance of the Sysmon service on a large number of computers.☆82Updated last year
- Dashboards for conducting forensic investigation using windows events in Kibana☆17Updated 5 years ago
- Threat intelligence and threat detection indicators (IOC, IOA)☆53Updated 4 years ago
- automate your MISP installs☆66Updated 4 years ago
- An ELK environment containing interesting security datasets.☆134Updated 4 years ago
- ansible role to setup MISP, Malware Information Sharing Platform & Threat Sharing☆53Updated 2 months ago
- A Splunk Technology Add-on to forward filtered ETW events.☆30Updated 4 years ago
- Cisco Orbital - Osquery queries by Talos☆130Updated 5 months ago
- Threat hunting repo for my independent study on threat hunting with OSQuery☆28Updated 7 years ago
- OSSEM Common Data Model☆55Updated 2 years ago
- pollen - A command-line tool for interacting with TheHive☆35Updated 5 years ago
- ☆12Updated 5 years ago
- ☆34Updated 4 years ago
- Threat Alert Logic Repository☆92Updated 6 years ago
- ☆18Updated 3 years ago
- This is a repository from Adam Swan and I's presentation on Windows Logs Zero 2 Hero.☆22Updated 7 years ago
- Elastic Beat for fetching and shipping Office 365 audit events☆66Updated 4 years ago