shadawck / awesome-endpoint-detection-and-responseLinks
Collection of tool you need to have in your Endpoint Detection and Response arsenal
☆111Updated last year
Alternatives and similar repositories for awesome-endpoint-detection-and-response
Users that are interested in awesome-endpoint-detection-and-response are comparing it to the libraries listed below
Sorting:
- Data visualization for blue teams☆127Updated 2 years ago
- ☆33Updated 2 months ago
- yara detection rules for hunting with the threathunting-keywords project☆157Updated 7 months ago
- Repository of tools and resources for analyzing Docker containers☆71Updated 2 years ago
- A Ruleset to enhance detection capabilities of Ossec using Sysmon☆94Updated 3 years ago
- File analysis and management framework.☆92Updated 2 years ago
- IOCs published by Black Lotus Labs☆124Updated 2 months ago
- Further investigation in to APT campaigns disclosed by private security firms and security agencies☆87Updated 3 years ago
- OpenCTI–Wazuh connector looking for indicators in Wazuh and creating sightings☆22Updated last year
- Threat Intel Platform for T-POTs☆160Updated this week
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Updated 3 years ago
- Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives …☆167Updated last year
- This repository is for Indicators of Compromise (IOCs) from Zscaler ThreatLabz public reports☆75Updated 3 weeks ago
- Fast IOC and YARA Scanner☆87Updated 5 years ago
- Blue Team detection lab created with Terraform and Ansible in Azure.☆175Updated last year
- QuickSand document and PDF malware analysis tool written in Python☆134Updated 2 months ago
- How to setup a honeypot with an IDS, ELK and TLS traffic inspection☆164Updated 3 years ago
- MITRE Engage™ is a framework for conducting Denial, Deception, and Adversary Engagements.☆67Updated last year
- A Self-Contained Open-Source Cyberattack Experimentation Testbed☆43Updated 6 months ago
- This repository contains analysis scripts, YARA rules, and additional IoCs related to our Telekom Security blog posts.☆119Updated 2 years ago
- Memory Forensic System on Cloud☆92Updated 2 years ago
- Roota is a public-domain language of threat detection and response that combines native queries from a SIEM, EDR, XDR, or Data Lake with …☆132Updated last year
- Anything Sysmon related from the MSTIC R&D team☆155Updated last year
- Website for ail-typo-squatting library☆68Updated 2 months ago
- Cyber Threat Intelligence Data, Indicators, and Analysis☆104Updated last month
- BlueBox Malware analysis Box and Cyber threat intelligence.☆45Updated 3 years ago
- A semi-curated list of Security Feeds☆143Updated 3 years ago
- Small web frontend for using openAI's GPT-3.5 and GPT-4's API☆59Updated 8 months ago
- Security Onion + Automation + Response Lab including n8n and Velociraptor☆112Updated 3 years ago
- ☆70Updated 4 years ago