ocsf / examples
This repo contains example of raw event examples and possible translations to the OCSF schema.
☆38Updated 2 weeks ago
Alternatives and similar repositories for examples:
Users that are interested in examples are comparing it to the libraries listed below
- ☆32Updated 2 months ago
- This is a repository of vendor-agnostic workflows provided for those interested in deploying Security Orchestration, Automation, and Resp…☆85Updated 4 years ago
- Convert cloudtrail data to MITRE ATT&CK Sightings☆80Updated 2 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 weeks ago
- Splunk Content Control Tool☆112Updated this week
- OCSF Documentation☆129Updated this week
- STIX2 graph visualisation library in JS☆90Updated 3 months ago
- Security Analytics enables users for detecting security threats on their security event log data. It will also allow them to modify/tailo…☆81Updated this week
- OCSF (https://schema.ocsf.io/) models in Python using Pydantic.☆22Updated this week
- ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit l…☆162Updated 2 months ago
- OASIS TC Open Repository: Validator for STIX 2.0 JSON normative requirements and best practices☆51Updated last month
- ☆43Updated last month
- A Software as a Service (SaaS) log collection framework.☆168Updated last week
- Knowledge Report Alert & Normalization Generator☆27Updated last year
- Anvilogic Forge☆103Updated this week
- ☆46Updated 11 months ago
- Command line tool for working with Panther rules and policies☆39Updated last week
- Automated testing, generation & manipulation of #osquery packs☆72Updated 6 months ago
- Audit log wall of shame.☆41Updated 6 months ago
- OCSF Schema Validation☆10Updated 4 months ago
- Security Alert Decoration☆27Updated 2 weeks ago
- Cloud Analytics helps defenders detect attacks to their cloud infrastructure by developing behavioral analytics for cloud platforms as we…☆53Updated 2 years ago
- An application allowing users to explore, create, annotate, and share extensions of the MITRE ATT&CK® knowledge base. This repository con…☆46Updated last week
- Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )☆179Updated 8 months ago
- OCA-wide documentation shared by all sub-projects and repositories☆33Updated 6 months ago
- OSSEM Common Data Model☆55Updated 2 years ago
- Posture Attribute Collection and Evaluation☆23Updated last year
- CrowdStrike Container Image Scan Github Action☆16Updated 6 months ago
- Swagger/ OpenAPI specifications for security products and services☆76Updated last month
- Examples on how to maintain security/compliance as code and to automate SecOps using the JupiterOne platform.☆53Updated last year