op7ic / amphuntLinks
This repository contains advanced threat hunting scripts for Cisco Secure Endpoint API. The scripts leverage the AMP API to hunt for threats, analyze endpoint behavior, and detect potential compromises across the environment using API version 0 and 1.
☆14Updated 5 months ago
Alternatives and similar repositories for amphunt
Users that are interested in amphunt are comparing it to the libraries listed below
Sorting:
- Incident Response Network Tools☆24Updated 4 years ago
- This repository contains all the config files and scripts used for our Open Source Endpoint monitoring project.☆35Updated 6 years ago
- Integrating Sysinternals Autoruns’ logs into Security Onion☆31Updated last year
- Triage automation for suspect URLs☆13Updated 6 years ago
- THOR MITRE ATT&CK Framework Coverage☆25Updated 5 years ago
- Splunk App to assist Sysmon Threat Hunting☆38Updated 8 years ago
- ☆13Updated 6 years ago
- PowerSponse is a PowerShell module focused on targeted containment and remediation during incident response.☆39Updated 3 years ago
- A simple ReST server to lookup threat actors (by name, synonym or UUID) and returning the corresponding MISP galaxy information about the…☆50Updated 3 months ago
- PowerShell Memory Pulling script☆19Updated 10 years ago
- Defence Against the Dark Arts☆34Updated 6 years ago
- ☆39Updated 5 years ago
- Connect your mail client/infrastructure to MISP in order to create events based on the information contained within mails.☆69Updated 2 years ago
- repo for sharing stuff☆17Updated 5 months ago
- A simple many-rules to many-files YARA scanner for incident response or malware zoos.☆27Updated 7 years ago
- automate your MISP installs☆68Updated 5 years ago
- Information about most important hunts which can be performed by Threat hunters while searching for any adversary/threats inside the orga…☆15Updated 6 years ago
- An extendable tool to extract and aggregate IoCs from threat feeds☆34Updated last year
- pollen - A command-line tool for interacting with TheHive☆36Updated 6 years ago
- Threat intelligence and threat detection indicators (IOC, IOA)☆52Updated 5 years ago
- Wrap any binary into a cached webserver☆56Updated 3 years ago
- Snapshot, patch, health-check, and potentially roll-back Windows VMs☆35Updated 7 years ago
- The "DFUR" Splunk application and data that was presented at the 2020 SANS DFIR Summit.☆13Updated 5 years ago
- A script to assist in processing forensic RAM captures for malware triage☆26Updated 4 years ago
- Python parser for Red Canary's Atomic Red Team Yamls☆27Updated 6 years ago
- An Installation Script for Bro IDS on Debian Based Systems☆20Updated 5 years ago
- A tool to assess data quality, built on top of the awesome OSSEM.☆79Updated 3 years ago
- Indicator of Compromise Scanner for CVE-2019-19781☆94Updated 5 years ago
- Traceroute improved wrapper for CSIRT and CERT operators☆39Updated last year
- incident response scripts☆19Updated 6 years ago