sublime-security / sublime-platformLinks
A free and open platform for detecting and preventing email attacks like BEC, malware, and credential phishing. Gain visibility and control, hunt for advanced threats, collaborate with the community, and write detections-as-code.
☆236Updated last month
Alternatives and similar repositories for sublime-platform
Users that are interested in sublime-platform are comparing it to the libraries listed below
Sorting:
- Roota is a public-domain language of threat detection and response that combines native queries from a SIEM, EDR, XDR, or Data Lake with …☆132Updated last year
- Sublime rules for email attack detection, prevention, and threat hunting.☆331Updated this week
- Volatile Artifact Collector collects a snapshot of volatile data from a system. It tells you what is happening on a system, and is of par…☆256Updated 11 months ago
- Save toil in security operations with: Detection & Intelligence Analysis for New Alerts (D.I.A.N.A. )☆221Updated last year
- A security analysis tool that identifies DNS queries made by browser extensions, empowering security teams to detect and investigate susp…☆184Updated 9 months ago
- MISP Playbooks☆216Updated 3 weeks ago
- A tool that allows you to document and assess any security automation in your SOC☆47Updated last year
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆165Updated last month
- An opensource sigma conversion tool built using pysigma☆145Updated 3 weeks ago
- SOARCA - The Open Source CACAO-based Security Orchestrator!☆93Updated 2 months ago
- An index of publicly available and open-source threat detection rulesets.☆129Updated 6 months ago
- CTI Blueprints is a free suite of templates and tools that helps Cyber Threat Intelligence analysts create high-quality, actionable repor…☆270Updated 7 months ago
- Docker image for MISP☆135Updated 2 months ago
- LotL RMM☆250Updated 2 weeks ago
- This is a collection of threat detection rules / rules engines that I have come across.☆299Updated last year
- Playbook-NG is a stateless web-based application used to match incident findings with countermeasures for adversary containment and evict…☆151Updated 3 weeks ago
- A community-driven repository for threat hunting ideas, methodologies, and research that serves as a central gathering place for hunters …☆284Updated this week
- Convert Sigma rules to SIEM queries, directly in your browser.☆96Updated 2 weeks ago
- Docker image for Velocidex Velociraptor☆139Updated 8 months ago
- A standard for reducing log volume without sacrificing analytical capability☆211Updated 8 months ago
- ☆88Updated 8 months ago
- ☆98Updated last week
- Anvilogic Forge☆110Updated last month
- Convert a variety of log formats to CSV while enriching detected IPs with Geolocation, ASN, DNS, WhoIs, Shodan InternetDB and Threat Indi…☆108Updated last year
- Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis…☆409Updated last month
- Threat Intel Platform for T-POTs☆156Updated this week
- This directory features proven systems that demonstrate value to your threat-informed efforts using metrics.☆114Updated 11 months ago
- Rules generated from our investigations.☆202Updated 4 months ago
- Security Onion + Automation + Response Lab including n8n and Velociraptor☆112Updated 3 years ago
- A library of Incident Response notebooks using Jupyter. We will show how you can leverage pre-defined notebook files to guide your incide…☆150Updated last year