Automatically generated Sysmon parser for Azure Sentinel
☆18Jan 6, 2026Updated 6 months ago
Alternatives and similar repositories for sysmon-parser
Users that are interested in sysmon-parser are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- ☆18Oct 20, 2022Updated 3 years ago
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆17Mar 13, 2026Updated 4 months ago
- Azure Sentinel Template parser☆16Nov 2, 2020Updated 5 years ago
- Beginners Guide to Hunting for Threats☆21Apr 26, 2025Updated last year
- Check you Sentinel environment using Pester infrastructure tests☆31Sep 26, 2023Updated 2 years ago
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- Threat Hunt Investigation Methodology and Procedure☆15Jul 11, 2022Updated 4 years ago
- Azure-Sentinel-BYOML☆14Nov 8, 2019Updated 6 years ago
- Azure OpenAI Playbook created for Microsoft Sentinel☆14May 2, 2024Updated 2 years ago
- Execute Shellcode And Other Goodies From MMC☆13Jun 17, 2015Updated 11 years ago
- Sentinel Recon Tools Workbook☆14Aug 24, 2022Updated 3 years ago
- putting all together: customer environment, some threats, azure security services, Microsoft 365 Defender services, Azure monitor service…☆18Apr 11, 2022Updated 4 years ago
- Installs And Executes Shellcode☆12Jul 26, 2015Updated 10 years ago
- Bulk turn on Analytic rules in Azure Sentinel☆18Oct 7, 2021Updated 4 years ago
- ☆15May 11, 2026Updated 2 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- ☆11Mar 16, 2023Updated 3 years ago
- Miscellaneous notebooks to use with Sentinel Hub☆20Aug 28, 2023Updated 2 years ago
- CIFv3 Ubuntu 16.04 Docker Container (Bearded Avenger)☆12Apr 18, 2018Updated 8 years ago
- Azure Function for the Microsoft Sentinel Triage AssistanT (STAT)☆16Apr 13, 2026Updated 3 months ago
- Integration tools for TheHive and Azure Sentinel☆13Sep 23, 2020Updated 5 years ago
- A collection of things I've created or found that I think is useful for Azure Sentinel.☆18Jul 8, 2026Updated last week
- ☆14Feb 22, 2021Updated 5 years ago
- Terraform module to send CloudWatch logs to a syslog server. Compatible with papertrail, logstash, and datadog.☆12Mar 18, 2021Updated 5 years ago
- Notes and utilities for reverse engineering Agilent PCIe Protocol Analyzers and their host software.☆14Jul 2, 2026Updated 2 weeks ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Miscellaneous Azure Sentinel files that don't fall into other categories.☆13Aug 23, 2021Updated 4 years ago
- KQL Sentinel and Defender Detection and Hunting Queries.☆16Jul 8, 2026Updated last week
- Leghorn code for PKI abuse☆34Jun 17, 2021Updated 5 years ago
- Detect and trap IP scanners☆11Mar 26, 2019Updated 7 years ago
- PowerShell commands to export the Azure Sentinel Rule Templates to a CSV and to create the Rules from selected entries in the CSV file☆17Oct 31, 2024Updated last year
- Extension that allows native HLS playback in Firefox browser☆13Sep 5, 2016Updated 9 years ago
- Manage your detectors and identify atypical data in OpenSearch Dashboards☆38Updated this week
- ☆15Jun 27, 2024Updated 2 years ago
- Send High & New Incidents to The Hive incident management Platform☆18Feb 13, 2021Updated 5 years ago
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Various commands, tools, techniques that you can use to examine live Windows systems for signs of Compromise or for Threat Hunting.Can al…☆15May 30, 2026Updated last month
- Misc. content for Microsoft Sentinel☆17Apr 12, 2024Updated 2 years ago
- A sysmon configuration designed for monitoring RMM solutions from the LOLRMM framework on the OS Microsoft Windows. 10/11☆33Feb 17, 2026Updated 5 months ago
- Splunk Technology-AddOn for Aurora Sigma-Based EDR Agent. It helps parse and configure the necessary inputs to neatly consume Aurora EDR …☆13Sep 27, 2022Updated 3 years ago
- This package allows for creating alerts in The Hive from emails retrieved from a Microsoft Exchange mailbox.☆12Jul 13, 2017Updated 9 years ago
- A PoC exploit for CVE-2023-51467 - Apache OFBiz Authentication Bypass☆12Dec 31, 2023Updated 2 years ago
- Ruby wrapper for dbgeng.dll☆18Aug 8, 2015Updated 10 years ago