rcegan / ConvertSigmaRepo2KQLLinks
A small crappy script I wrote that converts the Sigma Windows Process Creation events to KQL via PySigma. Designed for CI/CD
☆8Updated last year
Alternatives and similar repositories for ConvertSigmaRepo2KQL
Users that are interested in ConvertSigmaRepo2KQL are comparing it to the libraries listed below
Sorting:
- Velociraptor Server hosted in Azure App Service☆56Updated last month
- Hunting Queries for Defender ATP☆81Updated 3 months ago
- ☆43Updated 4 years ago
- ESXi Cyber Security Incident Response Script☆24Updated 10 months ago
- Hunting Queries for Microsoft Defender Security Center https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defe…☆39Updated 4 years ago
- ☆33Updated 3 years ago
- ☆42Updated 2 years ago
- Azure function to insert MISP data in to Azure Sentinel☆32Updated 2 years ago
- Sigma detection rules for hunting with the threathunting-keywords project☆56Updated 4 months ago
- Pushes Sysmon Configs☆88Updated 4 years ago
- Cheat sheets for threat hunting, detection and other stuff.☆34Updated 2 years ago
- ☆40Updated 2 weeks ago
- Provides an advanced baseline to implement a secure Windows auditing strategy on Windows OS.☆55Updated last month
- ☆22Updated 2 years ago
- A preconfigured Windows-based system designed for rapid forensic investigations in both Azure and AWS.☆39Updated last year
- Library of threat hunts to get any user started!☆44Updated 4 years ago
- Full of public notes and Utilities☆127Updated 5 months ago
- ☆73Updated 9 months ago
- Security Content for the PEAK Threat Hunting Framework☆31Updated last year
- ☆11Updated 3 years ago
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆91Updated 3 weeks ago
- ☆47Updated 3 months ago
- ☆35Updated 9 months ago
- This repository is used by FalconForce to release parts of the internal tools used for maintaining, validating and automatically deployin…☆17Updated 2 years ago
- Invoke-Forensics provides PowerShell commands to simplify working with the forensic tools KAPE and RegRipper.☆115Updated last year
- Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting☆65Updated 3 months ago
- Jupyter notebooks☆25Updated 4 years ago
- Script to automate Linux live evidence collection☆27Updated 2 years ago
- ☆53Updated 2 months ago
- Slides of my public talks☆56Updated last year