misje / wazuh-openctiLinks
Wazuh extension looking up alert data against indicators in OpenCTI threat intel
☆20Updated last year
Alternatives and similar repositories for wazuh-opencti
Users that are interested in wazuh-opencti are comparing it to the libraries listed below
Sorting:
- ☆35Updated last year
- ☆19Updated 3 years ago
- OpenCTI–Wazuh connector looking for indicators in Wazuh and creating sightings☆18Updated 11 months ago
- Personal scripts☆15Updated 10 months ago
- Sysmon and wazuh integration with Sigma sysmon rules [updated]☆67Updated 3 years ago
- Collection of Dashboards for Threat Hunting and more!☆68Updated 4 years ago
- Import CrowdStrike Threat Intelligence into your instance of MISP☆47Updated last month
- Roota is a public-domain language of threat detection and response that combines native queries from a SIEM, EDR, XDR, or Data Lake with …☆128Updated 11 months ago
- Integrate your Wazuh-Manager or Graylog with the SOCFortress Threat Intel Service☆29Updated 9 months ago
- A collection of various SIEM rules relating to malware family groups.☆66Updated last year
- Convert Sigma rules to Wazuh rules☆67Updated last year
- The Enhanced MITRE ATT&CK® Coverage Tracker is an Excel tool for SOCs to measure and improve detection coverage of cyber threats. It simp…☆27Updated 6 months ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆70Updated 2 years ago
- Practical Threat Detection Engineering, Published by Packt☆75Updated 2 years ago
- The official Prelude SIEM GitHub of https://www.prelude-siem.org☆31Updated 9 years ago
- Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents☆44Updated last year
- Cheat sheets for threat hunting, detection and other stuff.☆34Updated 2 years ago
- MISP Playbooks☆206Updated last month
- A Ruleset to enhance detection capabilities of Ossec using Sysmon☆94Updated 3 years ago
- Docker image for Velocidex Velociraptor☆129Updated 4 months ago
- Sigma detection rules for hunting with the threathunting-keywords project☆55Updated 4 months ago
- A production ready Dockered MISP☆255Updated last week
- ☆51Updated 3 years ago
- A collection of tips for using MISP.☆74Updated 7 months ago
- Open Source Platform for storing, organizing, and searching documents related to cyber threats☆164Updated last year
- This repository contains Splunk queries to hunt some anomalies☆43Updated 2 years ago
- Workflows for Shuffle☆23Updated 2 years ago
- pySigma Splunk backend☆40Updated 2 months ago
- ☆17Updated 2 years ago
- Security Onion + Automation + Response Lab including n8n and Velociraptor☆110Updated 2 years ago