vmware-archive / eqrLinks
Event Query Router
☆12Updated 6 years ago
Alternatives and similar repositories for eqr
Users that are interested in eqr are comparing it to the libraries listed below
Sorting:
- Specifications used in the MISP project including MISP core format☆53Updated last month
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 3 months ago
- A Python implementation of the Community ID flow hashing standard☆24Updated 2 years ago
- Things to know when DFIR occurs near a vault deployment.☆44Updated 7 years ago
- Core incident handling plugins for aws_ir cli, incident pony, and more.☆21Updated 7 years ago
- This python scripts can calculate the WHOIS Similarity Distance between two given domains.☆29Updated 3 years ago
- Structured Threat Intelligence Graph☆99Updated last month
- Python samples and utilities for Chronicle APIs☆88Updated 3 months ago
- Automation of VPC Traffic Mirror Sessions in AWS☆35Updated 2 months ago
- OASIS TC Open Repository: Match STIX content against STIX patterns☆46Updated 3 years ago
- The clever vulnerability dependency finder☆96Updated 3 years ago
- Tools for AWS forensics☆65Updated 9 years ago
- Firepit - STIX Columnar Storage☆17Updated last year
- Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)☆52Updated 3 years ago
- Fang and defang indicators of compromise. You can test this project in a GUI here: http://ioc-fanger.hightower.space .☆68Updated 2 years ago
- ☆83Updated 6 years ago
- Pythonic way to work with the warning lists defined there: https://github.com/MISP/misp-warninglists☆35Updated last month
- A Terraform module for GRR: the distributed incident forensics and response framework☆52Updated 5 years ago
- This repo contains example of raw event examples and possible translations to the OCSF schema.☆52Updated 6 months ago
- ☆35Updated 4 years ago
- OASIS TC Open Repository: Validator for STIX 2.0 JSON normative requirements and best practices☆60Updated 3 weeks ago
- This script is used to generate some basic detections of the aws security services☆72Updated 3 years ago
- A Python library to help with some common threat hunting data analysis operations☆143Updated 2 years ago
- Create complex tools execution Workflows for working together☆23Updated 4 years ago
- A RESTful API frontend for Stenographer☆54Updated 3 years ago
- A Lambda-powered Security Orchestration framework for AWS GuardDuty☆53Updated 6 years ago
- Zeek support for Community ID flow hashing.☆37Updated 2 years ago
- Provide a shell like interface by utilizing osquery's distributed API☆82Updated 5 years ago
- Notes for High Availability MISP in AWS☆19Updated 6 years ago
- 'Continuous' AWS perimeter monitoring: Periodically scan internet facing AWS resources to detect misconfigured services.☆64Updated 6 years ago