misje / wazuh-opencti
Wazuh extension looking up alert data against indicators in OpenCTI threat intel
☆17Updated 11 months ago
Alternatives and similar repositories for wazuh-opencti:
Users that are interested in wazuh-opencti are comparing it to the libraries listed below
- ☆33Updated last year
- A production ready Dockered MISP☆190Updated this week
- Docker image for MISP☆121Updated this week
- (Unofficial) Wazuh integration to send alerts to IRIS.☆16Updated 2 weeks ago
- Personal scripts☆12Updated 4 months ago
- SOCFortress CoPilot☆238Updated this week
- Convert Sigma rules to Wazuh rules☆59Updated 9 months ago
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆136Updated this week
- ☆31Updated 3 years ago
- Integrate your Wazuh-Manager or Graylog with the SOCFortress Threat Intel Service☆28Updated 3 months ago
- MISP Playbooks☆182Updated last month
- Docker image for Velocidex Velociraptor☆116Updated 6 months ago
- IRIS Module to Run Any Velociraptor Artifact☆12Updated last year
- Open Source Platform for storing, organizing, and searching documents related to cyber threats☆159Updated last year
- Useful scripts for those administering Wazuh☆79Updated this week
- OpenCTI Docker deployment helpers☆168Updated this week
- This is the One Stop place where you can find almost all of your Tools of Requirements in DFIR☆75Updated 2 years ago
- A Ruleset to enhance detection capabilities of Ossec using Sysmon☆87Updated 2 years ago
- OpenCTI–Wazuh connector looking for indicators in Wazuh and creating sightings☆16Updated 5 months ago
- ☆51Updated 8 months ago
- ☆13Updated last year
- These are open source rules that can be utilized with QRadar to detect various types of threats in the environment.☆52Updated 5 years ago
- Roota is a public-domain language of threat detection and response that combines native queries from a SIEM, EDR, XDR, or Data Lake with …☆121Updated 6 months ago
- Advanced Wazuh Rules for more accurate threat detection. Feel free to implement within your own Wazuh environment, contribute, or fork!☆643Updated this week
- CTI Blueprints is a free suite of templates and tools that helps Cyber Threat Intelligence analysts create high-quality, actionable repor…☆214Updated last year
- Repository of SentinelOne Deep Visibility queries.☆120Updated 3 years ago
- ☆204Updated 8 months ago
- Cyber Incident Response Team Playbook Battle Cards☆363Updated 8 months ago
- Import CrowdStrike Threat Intelligence into your instance of MISP☆42Updated 2 months ago
- MISP to Sentinel integration☆62Updated last month