Psipher Diaz's repositories
Antiphishing
Suricata rulesets for protect against phishing attack.
daemonloggerdaq
Daemonlogger modified to use DAQ, primarily for listening on multiple interfaces
ecs-mapping
Grab bag of resources for mapping data to the Elastic Common Schema (ECS)
incident-response-plan-template
A concise, directive, specific, flexible, and free incident response plan template
xdr-elk-stack
Logstash config to ingest Cortex XDR alerts
ansible-pull-example
example skeleton repo for setting up ansible-pull infrastructure
ansible-suricata
Ansible Role that installs and configures suricata
applookup
Package applookup for zeek
beats
:tropical_fish: Beats - Lightweight shippers for Elasticsearch & Logstash
bro-react
react stuff
elastic-detection-lab
This repository serves as a comprehensive recap and detailed write-up showcasing the successful completion and in-depth understanding of TCM Security's course: Detection Engineering for Beginners.
Elastic-Security
Repo for Automations and other solutions for Elastic SIEM/Security.
ixgbe-x540-bypass-linux-support
Set of patches for supporting Intel(R) 10GbE PCI Express X540T2BP bypass functions on the Linux Kernel.
sagan
Sagan is a multi-threads, high performance log analysis engine. At it's core, Sagan similar to Suricata/Snort but with logs rather than network packets.
suri-rule-gen
Suricata Rule Generation Scripts
suricata
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine developed by the OISF and the Suricata community.
suricata-update
The tool for updating your Suricata rules.
Suricata_IDS_IP_Reputation_Based_Detection
Using Suricata with bash scripting to detect malicious IPs. The script update-mdl.sh downloads a list of IP addresses and a list of Malicious IPs. These lists are compared to one another and a rating is applied based on the number of occurances.
vmtouch
Portable file system cache diagnostics and control
wec_pepped
Pep up your Windows Event Collector (WEC) for Windows Event Forwarding (WEF)
zeek_globalwhitelist
Logstretch public files