Splunk app for Threat hunting
☆15Nov 15, 2018Updated 7 years ago
Alternatives and similar repositories for SA-Threat-Hunting
Users that are interested in SA-Threat-Hunting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Splunk Searches and Dashboards for DNS Threat Hunting☆11Mar 5, 2018Updated 8 years ago
- Python script to run battery of Volatility plugins against a forensic memory image☆10Jun 22, 2019Updated 6 years ago
- ☆12Mar 24, 2018Updated 8 years ago
- See more current version at https://github.com/ElectionDataAnalysis/election_data_analysis/☆10Jul 6, 2023Updated 2 years ago
- Set Operations App for Splunk☆10Mar 29, 2021Updated 5 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Splunk App to assist Sysmon Threat Hunting☆38Mar 7, 2017Updated 9 years ago
- Basic demo for Hidden Treasure talk.☆49Nov 4, 2017Updated 8 years ago
- Splunk Technology Add-On (TA) for collecting ETW events from Windows systems☆16Dec 8, 2022Updated 3 years ago
- carcass is a Python package to generate python package scaffolding based on best practices☆17Jan 10, 2022Updated 4 years ago
- SDK for Developing Solutions in Splunk Enterprise with Python☆18May 18, 2026Updated last month
- Sample queries for Advanced hunting in Windows Defender ATP☆11Apr 22, 2020Updated 6 years ago
- An automated firmware analysis tool based on Firmadyne (https://github.com/firmadyne/firmadyne)☆24Jul 8, 2017Updated 8 years ago
- Exports MISP events to STIX and ingest into McAfee ESM☆15Feb 12, 2020Updated 6 years ago
- A website about DC's Advisory Neighborhood Commission system.☆43Apr 3, 2019Updated 7 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Analytics for Accounting logs from Network devices☆18Mar 27, 2021Updated 5 years ago
- An Incident Response tool that visualizes historic process execution evidence (based on Event ID 4688 - Process Creation Event) in a tree…☆60Jan 30, 2018Updated 8 years ago
- A collection of things I've created or found that I think is useful for Azure Sentinel.☆18Jun 8, 2026Updated last week
- Splunk code (SPL) for serious threat hunters and detection engineers.☆293Jan 15, 2024Updated 2 years ago
- Deploy and maintain Symon through the Splunk Deployment Sever☆32Jul 30, 2020Updated 5 years ago
- Based on the Volatility framework, this script will run various plugins as well as create a timeline, or use YARA/ClamAV/VirusTotal to fi…☆49May 31, 2017Updated 9 years ago
- A central place for me to share interesting PSRemoting configurations☆16Jun 28, 2017Updated 8 years ago
- Sysmon Splunk App☆47Aug 21, 2018Updated 7 years ago
- Set of ultra technical notes about AD☆18Jun 17, 2018Updated 8 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Dashboards for conducting forensic investigation using windows events in Kibana☆18Apr 6, 2019Updated 7 years ago
- ☆15Mar 24, 2017Updated 9 years ago
- Show AV Processes list☆15Sep 30, 2020Updated 5 years ago
- This repo exists as a quick and dirty arsenal of methods and scripts to subvert .NET SSL/TLS certificate validation in PowerShell and pre…☆12Jan 28, 2017Updated 9 years ago
- ☆53Mar 4, 2019Updated 7 years ago
- Solana Dex Info for arbitrage bot☆17Sep 6, 2025Updated 9 months ago
- Konrads' Pen-Ultimate (Windows) Log File Parser☆14Dec 27, 2025Updated 5 months ago
- Sysmon configuration☆64Jul 12, 2018Updated 7 years ago
- Heos Binding for OpenHab☆13Feb 1, 2019Updated 7 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Small tools to assist with using Large Language Models☆12Nov 7, 2023Updated 2 years ago
- ☆55Mar 2, 2022Updated 4 years ago
- ☆13Feb 6, 2018Updated 8 years ago
- Volatility plugin to help identify DoublePulsar implant by listing the array of pointers SrvTransaction2DispatchTable from the srv.sys dr…☆16Aug 14, 2017Updated 8 years ago
- A simple utility to check the status of and/or disable SMBv1 on Windows system via Cb Response's Live Response functionality.☆15May 28, 2019Updated 7 years ago
- Argument Injection in Dragonfly Ruby Gem☆16May 26, 2021Updated 5 years ago
- ☆15Sep 24, 2024Updated last year