Configuration files for the SOF-ELK VM
☆1,727Jan 21, 2026Updated 2 months ago
Alternatives and similar repositories for sof-elk
Users that are interested in sof-elk are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A Powershell incident response framework☆1,644Nov 22, 2022Updated 3 years ago
- The Hunting ELK☆3,911Jun 1, 2024Updated last year
- ☆2,393Oct 14, 2023Updated 2 years ago
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,518Jan 12, 2026Updated 2 months ago
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆2,511Jan 12, 2026Updated 2 months ago
- Wordpress hosting with auto-scaling on Cloudways • AdFully Managed hosting built for WordPress-powered businesses that need reliable, auto-scalable hosting. Cloudways SafeUpdates now available.
- An informational repo about hunting for adversaries in your IT environment.☆1,858Nov 17, 2021Updated 4 years ago
- Automate the creation of a lab environment complete with security tooling and logging best practices☆4,932Jul 6, 2024Updated last year
- Re-play Security Events☆1,731Mar 20, 2024Updated 2 years ago
- Sources, configuration and how to detect evil things utilizing Microsoft Sysmon.☆938Dec 12, 2023Updated 2 years ago
- Windows Events Attack Samples☆2,534Jan 24, 2023Updated 3 years ago
- Fast Incident Response☆2,002Mar 24, 2026Updated 2 weeks ago
- A repository of sysmon configuration modules☆3,003Aug 21, 2024Updated last year
- Main Sigma Rule Repository☆10,279Updated this week
- PowerForensics provides an all in one platform for live disk forensic analysis☆1,429Nov 16, 2023Updated 2 years ago
- DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Super timeline all the things☆2,043Feb 10, 2026Updated last month
- Detect Tactics, Techniques & Combat Threats☆2,275Jan 21, 2026Updated 2 months ago
- A curated list of tools for incident response☆8,913Jul 18, 2024Updated last year
- Collaborative forensic timeline analysis☆3,301Mar 29, 2026Updated last week
- Investigate malicious Windows logon by visualizing and analyzing Windows event log☆3,147Oct 19, 2025Updated 5 months ago
- A toolset to make a system look as if it was the victim of an APT attack☆2,723Sep 23, 2025Updated 6 months ago
- Digging Deeper....☆3,869Updated this week
- TheHive is a Collaborative Case Management Platform, now distributed as a commercial version☆3,895Jul 25, 2025Updated 8 months ago
- Collect, Process, and Hunt with host based data from MacOS, Windows, and Linux☆506Oct 21, 2022Updated 3 years ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Automated deployment scripts for the RockNSM network hunting distribution.☆456Jul 2, 2023Updated 2 years ago
- Sysmon configuration file template with default high-quality event tracing☆5,453Jul 3, 2024Updated last year
- Digital Forensics artifact repository☆1,223Feb 11, 2026Updated last month
- A repository for using windows event forwarding for incident detection and response☆1,306Sep 8, 2025Updated 6 months ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆795Mar 28, 2026Updated last week
- Loki - Simple IOC and YARA Scanner☆3,740Jan 12, 2026Updated 2 months ago
- DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.☆572Dec 12, 2021Updated 4 years ago
- Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management☆3,110Apr 16, 2021Updated 4 years ago
- GRR Rapid Response: remote live forensics for incident response☆5,047Feb 16, 2026Updated last month
- NordVPN Special Discount Offer • AdSave on top-rated NordVPN 1 or 2-year plans with secure browsing, privacy protection, and support for for all major platforms.
- Open Source Security Events Metadata (OSSEM)☆1,288Feb 27, 2023Updated 3 years ago
- CyLR - Live Response Collection Tool☆720Jun 1, 2022Updated 3 years ago
- Actionable analytics designed to combat threats☆1,007May 25, 2022Updated 3 years ago
- TrustedSec Sysinternals Sysmon Community Guide☆1,391Feb 10, 2026Updated last month
- This repository serves as a place for community created Targets and Modules for use with KAPE.☆828Mar 12, 2026Updated 3 weeks ago
- Small and highly portable detection tests based on MITRE's ATT&CK.☆11,771Mar 30, 2026Updated last week
- SIFT☆538Feb 14, 2024Updated 2 years ago