splunk / macro-level-attack-trending
Aggregated ATT&CK technique reporting data. Presented at Splunk GovSummit December 2022
☆15Updated last month
Alternatives and similar repositories for macro-level-attack-trending:
Users that are interested in macro-level-attack-trending are comparing it to the libraries listed below
- Library of threat hunts to get any user started!☆42Updated 4 years ago
- Awesome Splunk SPL hunt queries that can be used to detect the latest vulnerability exploitation attempts & subsequent compromise☆60Updated 10 months ago
- pySigma Splunk backend☆36Updated last week
- Collects a listing of MITRE ATT&CK Techniques, then discovers Splunk ESCU detections for each technique☆65Updated 11 months ago
- Summiting the Pyramid is a research project focused on engineering cyber analytics to make adversary evasion more difficult. The research…☆35Updated last week
- Small-scale threat emulation and detection range built on Elastic and Atomic Redteam.☆37Updated last year
- MITRE Shield website☆19Updated 3 years ago
- Cyber Threats Detection Rules☆14Updated 2 months ago
- Automated detection rule analysis utility☆29Updated 2 years ago
- User Feedback Space of #MitreAssistant☆37Updated last year
- Repository for SPEED SIEM Use Case Framework☆53Updated 4 years ago
- A CALDERA plugin☆25Updated 7 months ago
- SigmaHQ pySigma CrowdStrike processing pipeline☆23Updated 4 months ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆51Updated 2 years ago
- This repository contains OpenIOC rules to aid in hunting for indicators of compromise and TTPs focused on Advanced Persistent Threat grou…☆23Updated last year
- ☆5Updated 4 months ago
- Merge of two major cyber adversary datasets, MITRE ATT&CK and ETDA/ThaiCERT Threat Actor Cards, enabling victim/motivation-adversary-tech…☆53Updated 2 years ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆76Updated last year
- ☆28Updated 4 years ago
- Intelligence around common attacker behaviors (MITRE ATT&CK TTPs), in the form of ATT&CK Navigator "layer" json files.☆34Updated 2 years ago
- Azure function to insert MISP data in to Azure Sentinel☆31Updated 2 years ago
- This CALDERA Plugin converts Adversary Emulation Plans from the Center for Threat Informed Defense☆30Updated this week
- A browser extension for threat hunting that provides one UI for different SIEMs/EDRs and simplifies investigation☆76Updated 9 months ago
- Python library for threat intelligence☆83Updated last month
- Sigma Detection Rule Repository☆87Updated 4 years ago
- This guide describes a process for developing Cyber Threat Intelligence Priority Intelligence Requirements☆116Updated last year
- Convert Sigma rules to LogRhythm searches☆20Updated 3 years ago
- Full of public notes and Utilities☆98Updated 2 weeks ago
- ☆13Updated 2 months ago
- A collection of Sigma rules organized by MITRE ATT&CK technique☆17Updated 3 years ago