siriussecurity / dettectinator
Dettectinator - The Python library to your DeTT&CT YAML files.
☆107Updated 2 weeks ago
Alternatives and similar repositories for dettectinator:
Users that are interested in dettectinator are comparing it to the libraries listed below
- Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques☆131Updated 11 months ago
- An opensource sigma conversion tool built using pysigma☆113Updated last month
- OSSEM Detection Model☆174Updated 2 years ago
- ☆93Updated 2 years ago
- A repository of my own Sigma detection rules.☆157Updated 4 months ago
- A repository to share publicly available Velociraptor detection content☆124Updated this week
- Rules generated from our investigations.☆191Updated 3 months ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆177Updated this week
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆60Updated 9 months ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆146Updated last year
- The principal objective of this project is to develop a knowledge base of the tactics, techniques, and procedures (TTPs) used by insiders…☆142Updated 4 months ago
- ☆82Updated 3 weeks ago
- OSSEM Data Dictionaries☆59Updated last week
- Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE…☆90Updated this week
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆75Updated 8 months ago
- Full of public notes and Utilities☆95Updated 2 months ago
- Sensor Mappings to ATT&CK is a collection of resources to assist cyber defenders with understanding which sensors and events can help det…☆49Updated 7 months ago
- Intel Retrieval Augmented Generation (RAG) Utilities☆90Updated last year
- A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon☆195Updated 4 years ago
- A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.☆193Updated 2 weeks ago
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆137Updated this week
- Detection Ideas & Rules repository.☆178Updated 3 years ago
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆115Updated last year
- ☆54Updated last year
- Resources To Learn And Understand SIGMA Rules☆173Updated last year
- ☆4Updated 3 months ago
- Adversarial Interception Mission Oriented Discovery and Disruption Framework, or AIMOD2, is a structured threat hunting approach to proac…☆85Updated last year
- ☆86Updated 5 months ago
- MISP to Sentinel integration☆62Updated 2 months ago
- SentinelOne STAR Rules☆54Updated last year