Just Someone's repositories

Sigma-Hunting-App

A Splunk App containing Sigma detection rules, which can be updated from a Git repository.

Language:PythonLicense:MITStargazers:1Issues:1Issues:0

ATTACK-Python-Client

Python Script to access ATT&CK content available in STIX via a public TAXII server

Language:PythonLicense:BSD-3-ClauseStargazers:0Issues:0Issues:0

browser-history

A simple, zero-dependencies, developer-friendly Python package to retrieve web browser history

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

corona_virus

This project includes an app that allows users to visualize and analyze information about COVID-19 using data made publicly-available by Johns Hopkins University. For more information on legal disclaimers, please see the README.

Language:PythonLicense:Apache-2.0Stargazers:0Issues:1Issues:0

docker-cuckoo

Cuckoo Sandbox Dockerfile

Language:ShellLicense:NOASSERTIONStargazers:0Issues:0Issues:0

docker-moloch

A Docker container for Moloch based on minimal Debian

Language:ShellLicense:MITStargazers:0Issues:1Issues:0

ldap-analyzer

Bro analyzer for LDAP write operations

Language:JavaScriptLicense:UnlicenseStargazers:0Issues:1Issues:0

Malcolm

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files) and Zeek logs.

Language:PythonLicense:NOASSERTIONStargazers:0Issues:1Issues:0

malwoverview

Malwoverview is a first response tool to perform an initial and quick triage in a directory containing malware samples, specific malware sample, suspect URL and domains. Additionally, it allows to download and send samples to main online sandboxes.

Language:PythonLicense:GPL-3.0Stargazers:0Issues:1Issues:0

PSSysmonTools

Sysmon Tools for PowerShell

Language:PowerShellLicense:BSD-3-ClauseStargazers:0Issues:1Issues:0

sigma

Main Sigma Rule Repository

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0

Sigma2SplunkAlert

Converts Sigma detection rules to a Splunk alert configuration.

Language:PythonLicense:MITStargazers:0Issues:1Issues:0

sigma_python_toolbox

My tools box script for sigma

Language:PythonStargazers:0Issues:0Issues:0

SLIPSDocker

Docker for Stratosphere Linux IPS

Language:ShellStargazers:0Issues:2Issues:0

sysmon-config

Sysmon configuration file template with default high-quality event tracing

Stargazers:0Issues:1Issues:0

ThreatHunting

A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

Language:PythonLicense:MITStargazers:0Issues:1Issues:0

uac

UAC is a Live Response collection script for Incident Response that makes use of native binaries and tools to automate the collection of AIX, Android, ESXi, FreeBSD, Linux, macOS, NetBSD, NetScaler, OpenBSD and Solaris systems artifacts.

Language:ShellLicense:Apache-2.0Stargazers:0Issues:0Issues:0
Language:TypeScriptLicense:MITStargazers:0Issues:0Issues:0
Stargazers:0Issues:2Issues:0

Zircolite

A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs

Language:PythonStargazers:0Issues:0Issues:0