ocsf / examples
This repo contains example of raw event examples and possible translations to the OCSF schema.
☆36Updated 2 weeks ago
Alternatives and similar repositories for examples:
Users that are interested in examples are comparing it to the libraries listed below
- ☆32Updated 7 months ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated last week
- Convert cloudtrail data to MITRE ATT&CK Sightings☆79Updated 2 years ago
- OCSF (https://schema.ocsf.io/) models in Python using Pydantic.☆18Updated this week
- OCSF Documentation☆122Updated last month
- Automated Forensics Orchestrator for Amazon EC2 is a self-service AWS Solution implementation that enterprise customers can deploy to qui…☆59Updated 2 months ago
- This is a repository of vendor-agnostic workflows provided for those interested in deploying Security Orchestration, Automation, and Resp…☆80Updated 3 years ago
- ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit l…☆156Updated 2 weeks ago
- ☆10Updated 2 months ago
- Automated testing, generation & manipulation of #osquery packs☆72Updated 4 months ago
- The SOCless automation framework☆137Updated this week
- OASIS TC Open Repository: Validator for STIX 2.0 JSON normative requirements and best practices☆51Updated 2 months ago
- This repository holds the necessary content to produce the D3FEND ontology distribution.☆64Updated this week
- Security Analytics enables users for detecting security threats on their security event log data. It will also allow them to modify/tailo…☆77Updated this week
- ☆40Updated last month
- STIX2 graph visualisation library in JS☆90Updated 2 weeks ago
- Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )☆167Updated 5 months ago
- ☆88Updated 11 months ago
- ☆12Updated 9 months ago
- Firepit - STIX Columnar Storage☆16Updated 8 months ago
- Python samples and utilities for Chronicle APIs☆80Updated last week
- Posture Attribute Collection and Evaluation☆24Updated last year
- Cloud security tutorials and best practices☆38Updated last year
- Coalfire AWS RAMP/pak Reference Architecture☆36Updated 5 months ago
- Audit log wall of shame.☆41Updated 3 months ago
- ☆65Updated 8 months ago
- ☆15Updated last year
- A Software as a Service (SaaS) log collection framework.☆148Updated 2 months ago
- OCA-wide documentation shared by all sub-projects and repositories☆33Updated 3 months ago
- A cheatsheet containing AWS CloudTrail events that can be used for Incident Response purposes or Detection Engineering.☆65Updated 9 months ago