Erick's repositories
threat-detection-engineering-reference
Resource for all things threat detection
AIMOD2
Adversarial Interception Mission Oriented Discovery and Disruption Framework, or AIMOD2, is a structured threat hunting approach to proactively identify, engage and prevent cyber threats denying or mitigating potential damage to the organization.
airthingsnest
Airthings + Nest Integration to maintain air quality and temp
angular-translate
Translating your AngularJS 1.x apps
appium
:iphone: Automation for iOS, Android, and Windows Apps.
atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
cartography
Cartography is a Python tool that consolidates infrastructure assets and the relationships between them in an intuitive graph view powered by a Neo4j database.
CortexDocs
Documentation of Cortex
docker-misp
Automated Docker MISP container - Malware Information Sharing Platform and Threat Sharing
falco
Cloud Native Runtime Security
maxmind-graphql
GraphQL API for MaxMind DB Reader
domainthreat
Newly registered Domain Monitoring to detect phishing and brand impersonation with subdomain enumeration and source code scraping
incident-notification-copy
Repo of customer notifications
insightconnect-plugins
Plugin source code for the InsightConnect SOAR product, developer documentation at komand.github.io/python/start.html
matterport-dl
A downloader for matterport virtual tours
MISP
MISP (core software) - Open Source Threat Intelligence and Sharing Platform (formely known as Malware Information Sharing Platform)
misp-modules
Modules for expansion services, import and export in MISP
my-arsenal-of-aws-security-tools
List of open source tools for AWS security: defensive, offensive, auditing, DFIR, etc.
osquery
SQL powered operating system instrumentation, monitoring, and analytics.
pandasql
sqldf for pandas
python-actions
GitHub Actions for Python packaging and distribution
sigma
Main Sigma Rule Repository
splunk-sdk-python
Splunk Software Development Kit for Python
stratus-red-team
:cloud: :zap: Granular, Actionable Adversary Emulation for the Cloud
streamalert
StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define. Also, we are hiring!!!!!!!!
templates
Document templates for open-source projects (README, CONTRIBUTING, GitHub templates)
verizon-dbir-reports
This is a repository of the Verizon DBIRs because the older ones are hard to find online.
vscode
Visual Studio Code