wazuh / wazuh-ruleset
Wazuh - Ruleset
☆421Updated last month
Related projects ⓘ
Alternatives and complementary repositories for wazuh-ruleset
- Wazuh - Project documentation☆195Updated this week
- Plugins for Wazuh Dashboard☆434Updated this week
- Scirius is a web application for Suricata ruleset management and threat hunting.☆633Updated 3 weeks ago
- Create actionable data from your Vulnerability Scans☆1,356Updated last year
- Documentation of Cortex☆170Updated last year
- Documentation of TheHive☆392Updated last year
- Wazuh - RESTful API☆68Updated last month
- Cortex: a Powerful Observable Analysis and Active Response Engine☆1,342Updated last week
- Cortex Analyzers Repository☆433Updated this week
- Suricata IDS/IPS log analytics using the Elastic Stack.☆231Updated 3 years ago
- Automated deployment scripts for the RockNSM network hunting distribution.☆446Updated last year
- IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.☆975Updated this week
- Mapping the MITRE ATT&CK Matrix with Osquery☆776Updated last year
- Security event correlation engine for ELK stack☆434Updated 4 months ago
- Python library using the MISP Rest API☆444Updated last week
- Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search☆429Updated this week
- Phantom Community Playbooks☆471Updated 2 weeks ago
- A Linux Auditd rule set mapped to MITRE's Attack Framework☆778Updated 4 years ago
- Wazuh - Tools for packages creation☆105Updated this week
- Main MineMeld documentation repo☆380Updated 7 years ago
- Configuration files for the SOF-ELK VM☆1,493Updated this week
- Suricata and Snort IDS rule and pcap testing system☆449Updated 2 weeks ago
- A set of Zeek scripts to detect ATT&CK techniques.☆563Updated 4 months ago
- Modules for expansion services, enrichment, import and export in MISP and other tools.☆344Updated last week
- MISP Docker (XME edition)☆283Updated 11 months ago
- Actionable analytics designed to combat threats☆972Updated 2 years ago
- Python API Client for TheHive☆218Updated this week
- Graylog Processing Pipeline functions to enrich log messages with IoC information from threat intelligence databases☆150Updated 8 months ago
- DPS' Lightweight Investigation Notebook☆423Updated 10 months ago
- Contains Logstash related content including tons of Logstash configurations☆253Updated 3 years ago