splunk / PEAK
Security Content for the PEAK Threat Hunting Framework
☆28Updated last year
Alternatives and similar repositories for PEAK:
Users that are interested in PEAK are comparing it to the libraries listed below
- ☆21Updated 2 years ago
- Library of threat hunts to get any user started!☆42Updated 4 years ago
- Sigma detection rules for hunting with the threathunting-keywords project☆55Updated 3 weeks ago
- Contains compiled binaries of Volatility☆33Updated 2 months ago
- A home for detection content developed by the delivr.to team☆67Updated last month
- Placeholder for my detection repo and misc detection engineering content☆43Updated last year
- Remote access and Antivirus Logging Database☆42Updated 10 months ago
- A preconfigured Velociraptor triage collector☆43Updated this week
- CarbonBlack EDR detection rules and response actions☆71Updated 6 months ago
- my MSTICpy practice and custom tools repository☆11Updated 4 months ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆76Updated last year
- Repository documenting how Threat Intelligence and / or a Threat Intelligence Platform can prove its value to an organisation.☆51Updated 5 months ago
- Slides of my public talks☆54Updated last year
- Baseline a Windows System against LOLBAS☆25Updated 11 months ago
- ESXi Cyber Security Incident Response Script☆23Updated 6 months ago
- Power-Forensics is the Best Friend for Incident Responders to perform IR and collect evidences for Linux based host☆11Updated last year
- Tools and scripts to deploy and manage OpenRelik instances☆13Updated last month
- ☆36Updated last month
- ☆30Updated 2 weeks ago
- Azure function to insert MISP data in to Azure Sentinel☆31Updated 2 years ago
- Helping Incident Responders hunt for potential persistence mechanisms on UNIX-based systems.☆15Updated last year
- This repository contains OpenIOC rules to aid in hunting for indicators of compromise and TTPs focused on Advanced Persistent Threat grou…☆23Updated last year
- YARA rule analyzer to improve rule quality and performance☆97Updated 3 months ago
- Quick ESXi Log Parser☆16Updated 2 months ago
- ☆86Updated last year
- An experimental script to perform bulk parsing of arbitrary file features with YARA and console logging.☆21Updated 2 years ago
- Jupyter Notebooks for Cyber Threat Intelligence☆36Updated last year
- Memory Baseliner is a script that can compare two windows memory images or perform frequency of occurrence / data stacking analysis on mu…☆52Updated last year
- Project based on RegRipper, to extract add'l value/pivot points from TLN events file☆84Updated last month
- ShellSweeping the evil.☆52Updated 9 months ago