ionstorm (ion-storm)

ion-storm

Geek Repo

Location:root@localhost

Twitter:@ionstorm

Github PK Tool:Github PK Tool

ionstorm's repositories

sysmon-config

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.

Language:PowerShellLicense:LGPL-2.1Stargazers:749Issues:86Issues:19

sysmon-edr

Sysmon EDR POC Build within Powershell to prove ability.

Language:YARAStargazers:4Issues:2Issues:0

exploitguard

Documentation and supporting script sample for Windows Exploit Guard

Language:PowerShellLicense:MITStargazers:3Issues:1Issues:0

cti

Cyber Threat Intelligence Repository expressed in STIX 2.0

License:NOASSERTIONStargazers:1Issues:1Issues:0
Language:PowerShellStargazers:1Issues:1Issues:0

SysmonCommon

The common parts of the Sysinternals Sysmon tool shared between the Windows and Linux versions.

Language:C++License:MITStargazers:1Issues:0Issues:0

ace-proctree

Create a cool process tree like https://twitter.com/ACEResponder.

Language:PythonStargazers:0Issues:0Issues:0
Language:TypeScriptLicense:Apache-2.0Stargazers:0Issues:1Issues:0

ConfluentCyberDemo

Analyze Zeek IDS data with ksqlDB running on Confluent Platform via Docker on your laptop. Or spin up an arbitrary number of AWS hosts, each running Confluent Platform and ksqlDB for use in an instructor-led workshop.

Language:PythonStargazers:0Issues:1Issues:0

cp-siem

A dockerized demo for illustrating how Confluent can be used in a SIEM Modernization use case.

Language:ShellStargazers:0Issues:1Issues:0
Language:JavaStargazers:0Issues:1Issues:0

DropNet

A tool that can be used to close network connections automatically with a given parameters

Language:PowerShellLicense:Apache-2.0Stargazers:0Issues:1Issues:0

falcon-query-assets

Welcome to the Falcon Query Assets GitHub page.

Stargazers:0Issues:0Issues:0

grafana

The open and composable observability and data visualization platform. Visualize metrics, logs, and traces from multiple sources like Prometheus, Loki, Elasticsearch, InfluxDB, Postgres and many more.

Language:TypeScriptLicense:Apache-2.0Stargazers:0Issues:1Issues:0

Graylog-Okta

An integration for Graylog and Okta

Language:PowerShellLicense:Apache-2.0Stargazers:0Issues:1Issues:0

humio-fdr-utils

Package to help around crowdstrike/fdr data

License:Apache-2.0Stargazers:0Issues:1Issues:0

k8s-go-sigma-streamer

Repo for project GoAhead talk at ShmooCon 2022

Language:GoLicense:NOASSERTIONStargazers:0Issues:1Issues:0
Language:JavaStargazers:0Issues:1Issues:0

ksql-extras

UDF/UDAFs for KSQL and example Queries.

Language:JavaLicense:Apache-2.0Stargazers:0Issues:1Issues:0

o365beat

Elastic Beat for fetching and shipping Office 365 audit events

Language:GoLicense:NOASSERTIONStargazers:0Issues:1Issues:0

ProcessBouncer

ProcessBouncer is a PoC for blocking malware with a process-based approach. With a little fine-tuning this allows to effectively block most of current ransomware that is out there.

Language:PowerShellLicense:GPL-3.0Stargazers:0Issues:1Issues:0

PS-SentinelOne

PowerShell module for SentinelOne API

Language:PowerShellLicense:MITStargazers:0Issues:1Issues:0
Language:PythonLicense:MITStargazers:0Issues:1Issues:0
License:Apache-2.0Stargazers:0Issues:1Issues:0

SentinelOne-ATTACK-Queries

MITRE ATT&CK mapped queries for SentinelOne Deep Visiblity

License:MITStargazers:0Issues:1Issues:0

sentinelone-queries

Repository of SentinelOne Deep Visibility queries.

License:LGPL-2.1Stargazers:0Issues:1Issues:0

sigma

Generic Signature Format for SIEM Systems

Language:PythonStargazers:0Issues:1Issues:0

solutions-terraform-jenkins-gitops

Demonstrates the use of Jenkins and Terraform to manage Infrastructure as Code using GitOps practices

Language:HCLLicense:Apache-2.0Stargazers:0Issues:1Issues:0