vmware-archive / eqrLinks
Event Query Router
☆12Updated 6 years ago
Alternatives and similar repositories for eqr
Users that are interested in eqr are comparing it to the libraries listed below
Sorting:
- Things to know when DFIR occurs near a vault deployment.☆44Updated 7 years ago
- Python samples and utilities for Chronicle APIs☆88Updated 3 months ago
- defendA Data Lake. A firehose pipeline to athena providing enrichment and normalization for security events☆17Updated 2 years ago
- Steve McCanne's Sharkfest '21 Talk☆16Updated 4 years ago
- Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)☆52Updated 3 years ago
- Bro/Zeek integration with osquery☆94Updated 5 years ago
- ☆83Updated 6 years ago
- Specifications used in the MISP project including MISP core format☆53Updated last month
- Core incident handling plugins for aws_ir cli, incident pony, and more.☆21Updated 7 years ago
- A Python library to help with some common threat hunting data analysis operations☆143Updated 2 years ago
- 'Continuous' AWS perimeter monitoring: Periodically scan internet facing AWS resources to detect misconfigured services.☆64Updated 6 years ago
- Tools for AWS forensics☆65Updated 9 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 3 months ago
- ☆25Updated 7 years ago
- OASIS TC Open Repository: Match STIX content against STIX patterns☆46Updated 3 years ago
- Firepit - STIX Columnar Storage☆17Updated last year
- Fang and defang indicators of compromise. You can test this project in a GUI here: http://ioc-fanger.hightower.space .☆68Updated 2 years ago
- The clever vulnerability dependency finder☆96Updated 3 years ago
- This script is used to generate some basic detections of the aws security services☆72Updated 3 years ago
- A Lambda-powered Security Orchestration framework for AWS GuardDuty☆53Updated 6 years ago
- A very simple CEF parser for Python☆28Updated 5 years ago
- Run Splunk heavy forwarders in Docker Swarm for high availability, security, and reduced cost!☆14Updated 5 months ago
- Python module for evaluation of AWS account best practices around incident handling readieness.☆55Updated 5 years ago
- SIAC is an enterprise SIEM built on open-source technology.☆115Updated 7 years ago
- Create complex tools execution Workflows for working together☆23Updated 4 years ago
- A command line security audit tool for Amazon Web Services☆82Updated 6 years ago
- A Python implementation of the Community ID flow hashing standard☆24Updated 2 years ago
- Osquery Mangement Server☆115Updated 5 years ago
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆124Updated 5 years ago
- This command line tool counts the number of resources in different categories across Amazon regions.☆59Updated 6 years ago