xme / SANS-ISC
Data related to the SANS Internet Storm Center
☆11Updated 5 years ago
Related projects ⓘ
Alternatives and complementary repositories for SANS-ISC
- Randori: Like Aiki. With a couple of Dans under its belt.☆14Updated 7 years ago
- References for FIRST CTI 2019 Symposium presentation☆23Updated 5 years ago
- YETI (Your Everyday Threat Intelligence) Integration to Elastic Stack☆15Updated 3 years ago
- pollen - A command-line tool for interacting with TheHive☆34Updated 5 years ago
- Force-Directed Graph Generator for Volatility Ouputs☆26Updated 5 years ago
- This is a repository from Adam Swan and I's presentation on Windows Logs Zero 2 Hero.☆21Updated 6 years ago
- Some rules, scripts of some use to us☆9Updated 3 weeks ago
- Build your own threat hunting maturity model☆12Updated 7 years ago
- Integrating Sysinternals Autoruns’ logs into Security Onion☆31Updated 9 months ago
- CIRCL system forensic tools or a jumble of tools to support forensic☆42Updated last year
- Plugins to add funtionality to ProcDOT. http://www.procdot.com☆22Updated last year
- A Python script for indexing (putting) FireEye alert data into Elasticsearch...and notifying you too.☆16Updated 5 years ago
- A collection of typical false positive indicators☆54Updated 3 years ago
- A collection of Python utilities for use in scripts related to working with "indicators of compromise" (IOCs).☆17Updated 5 years ago
- Web based analysis platform for use with the AWS_IR command line tool.☆17Updated 8 years ago
- Splunk app for Threat hunting☆15Updated 6 years ago
- Tools for parsing Forensic images☆41Updated 5 years ago
- ☆31Updated this week
- DocBleachShell is the integration of the great DocBleach, https://github.com/docbleach/DocBleach Content Disarm and Reconstruction tool i…☆21Updated 2 years ago
- Powershell Functions to interact with TheHive-Project☆10Updated 5 years ago
- OSSEC Decoder & Rulesets for Sysmon Events☆15Updated 9 years ago
- Just another tool to extract Indicator of compromise (ioc) from files☆28Updated 9 years ago
- Zeek package to generate a SMB client fingerprint☆26Updated 4 years ago
- This package allows for creating alerts in The Hive from emails retrieved from a Microsoft Exchange mailbox.☆12Updated 7 years ago
- A bunch of scripts I use to work with urlscan.io☆33Updated 5 years ago