socfortress / iris-velociraptorartifact-moduleLinks
IRIS Module to Run Any Velociraptor Artifact
☆15Updated 2 years ago
Alternatives and similar repositories for iris-velociraptorartifact-module
Users that are interested in iris-velociraptorartifact-module are comparing it to the libraries listed below
Sorting:
- A production ready Dockered MISP☆298Updated last week
- A centralized and enhanced memory analysis platform☆511Updated 5 months ago
- A collection of files with indicators supporting social media posts from Palo Alto Network's Unit 42 team to disseminate timely threat in…☆428Updated last week
- SOCFortress CoPilot☆417Updated last week
- Handbook of windows forensic artifacts across multiple Windows version with interpretation tips and some examples. Work in progress!☆443Updated last year
- MISP Playbooks☆222Updated 2 months ago
- 🏴☠️💰 Another Ransomware gang tracker☆271Updated 3 months ago
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆212Updated last week
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆402Updated last month
- Awesome list of keywords and artifacts for Threat Hunting sessions☆622Updated 4 months ago
- Playbooks for SOC Analysts☆639Updated 3 years ago
- Open Source Security Operations Center Documentation☆203Updated 5 months ago
- Automated YARA Rule Standardization and Quality Assurance Tool☆263Updated this week
- Harness the power of Splunk for your investigations☆145Updated 2 months ago
- CTI Blueprints is a free suite of templates and tools that helps Cyber Threat Intelligence analysts create high-quality, actionable repor…☆276Updated 9 months ago
- ☆164Updated last month
- An opensource sigma conversion tool built using pysigma☆152Updated last week
- ☆218Updated last year
- CLI tools for forensic investigation of Windows artifacts☆348Updated 5 months ago
- Documentation and scripts to properly enable Windows event logs.☆647Updated 2 months ago
- This project is a SIEM with SIRP and Threat Intel, all in one.☆464Updated last year
- Generate MITRE ATT&CK and D3FEND from a list of CVEs. Database with CVE, CWE, CAPEC, MITRE ATT&CK and D3FEND Techniques data is updated d…☆257Updated last week
- Docker image for Velocidex Velociraptor☆142Updated 9 months ago
- Purpleteam scripts simulation & Detection - trigger events for SOC detections☆192Updated last year
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆167Updated 3 weeks ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆291Updated last week
- ☆40Updated 2 years ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆765Updated 8 months ago
- CyberSecurity BLUE TEAM containerized platform that brings together open-source tools for SIEM, DFIR, CTI, SOAR, and Network Analysis☆405Updated 2 months ago
- Rapidly Search and Hunt through Linux Forensics Artifacts☆201Updated last year