scottleyg / SecOpsSamplesLinks
Sample SecOps scripts and Utilities
☆12Updated last year
Alternatives and similar repositories for SecOpsSamples
Users that are interested in SecOpsSamples are comparing it to the libraries listed below
Sorting:
- Cumulonimbus-UAL_Extractor is a PowerShell based tool created by the Tesorion CERT team to help gather the Unified Audit Logging out of a…☆21Updated 2 years ago
- A preconfigured Windows-based system designed for rapid forensic investigations in both Azure and AWS.☆40Updated last year
- ☆50Updated last week
- A list of RMMs designed to be used in automation to build alerts☆117Updated 2 months ago
- ☆28Updated 3 months ago
- Elastic version of SOC prime watcher rules☆30Updated last year
- ☆22Updated 3 years ago
- A repository to help CTI teams tackle the challenges around collection and research by providing guidance from experienced practitioners☆115Updated last year
- God Mode Detection Rules☆135Updated last year
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆77Updated last year
- Sigma detection rules for hunting with the threathunting-keywords project☆58Updated 11 months ago
- Domain Response is a tool that is designed to help you automate the investigation for a domain. This tool is specificly designed to autom…☆49Updated last month
- Repo containing various intel-based resources such as threat research, adversary emulation/simulation plan and so on☆83Updated last year
- Actively hunt for attacker infrastructure by filtering Shodan results with URLScan data.☆63Updated last year
- Examine Chrome extensions for security issues☆93Updated 2 months ago
- A CALDERA plugin☆27Updated last week
- Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents☆51Updated last year
- This repository is used by FalconForce to release parts of the internal tools used for maintaining, validating and automatically deployin…☆17Updated 2 years ago
- Conference presentations☆60Updated 3 months ago
- A collection of various SIEM rules relating to malware family groups.☆70Updated last year
- ETM enables the creation of detailed attack graphs and figures while calculating the risk associated with your attack narratives. ETM was…☆26Updated 2 years ago
- Ingesting Shodan Monitor Alerts to Microsoft Sentinel☆34Updated 2 years ago
- Open Threat Hunting Framework☆123Updated 2 years ago
- Anvilogic Forge☆114Updated 4 months ago
- ☆70Updated this week
- Intelligence around common attacker behaviors (MITRE ATT&CK TTPs), in the form of ATT&CK Navigator "layer" json files.☆36Updated 3 years ago
- Cyber Range including Velociraptor + HELK system with a Windows VM for security testing and R&D. Azure and AWS terraform support.☆145Updated 3 years ago
- A repository for tracking events related to the MOVEit Transfer Cl0p Campaign☆71Updated 2 years ago
- Cyber Threat Intelligence☆73Updated 2 months ago
- ☆33Updated 3 years ago