vmware-archive / eqrLinks
Event Query Router
☆12Updated 6 years ago
Alternatives and similar repositories for eqr
Users that are interested in eqr are comparing it to the libraries listed below
Sorting:
- ☆35Updated 4 years ago
- A very simple CEF parser for Python☆28Updated 5 years ago
- defendA Data Lake. A firehose pipeline to athena providing enrichment and normalization for security events☆16Updated 2 years ago
- Active Response plugin. Osquery to execute wazuh/ossec active response plugins. You can write your own plugins, easy to plug☆11Updated 5 years ago
- Python samples and utilities for Chronicle APIs☆86Updated 3 weeks ago
- Osquery Mangement Server☆114Updated 5 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 months ago
- OASIS TC Open Repository: Match STIX content against STIX patterns☆46Updated 3 years ago
- SIAC is an enterprise SIEM built on open-source technology.☆115Updated 7 years ago
- Run Splunk heavy forwarders in Docker Swarm for high availability, security, and reduced cost!☆14Updated 2 months ago
- Things to know when DFIR occurs near a vault deployment.☆43Updated 7 years ago
- OSSEM Common Data Model☆56Updated 3 years ago
- Bro scripts for the ROCK platform. http://rocknsm.io☆34Updated 2 years ago
- ☆25Updated 6 years ago
- ☆83Updated 5 years ago
- Tools for AWS forensics☆64Updated 9 years ago
- Bro/Zeek integration with osquery☆94Updated 5 years ago
- Firepit - STIX Columnar Storage☆16Updated last year
- Fang and defang indicators of compromise. You can test this project in a GUI here: http://ioc-fanger.hightower.space .☆65Updated 2 years ago
- A Python implementation of the Community ID flow hashing standard☆23Updated last year
- WebUI of MineMeld☆43Updated 2 years ago
- Specifications used in the MISP project including MISP core format☆52Updated this week
- A Python library to help with some common threat hunting data analysis operations☆143Updated 2 years ago
- Core incident handling plugins for aws_ir cli, incident pony, and more.☆21Updated 7 years ago
- OASIS TC Open Repository: Validate patterns used to express cyber observable content in STIX Indicators☆29Updated last year
- Python module for evaluation of AWS account best practices around incident handling readieness.☆55Updated 5 years ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆53Updated 3 years ago
- scan s3 buckets for security issues☆85Updated last year
- A collection of notebooks built for defensive and offensive operations.☆77Updated 5 years ago
- A Terraform module for GRR: the distributed incident forensics and response framework☆51Updated 5 years ago