ionstorm (ion-storm)

ion-storm

Geek Repo

Location:root@localhost

Twitter:@ionstorm

Github PK Tool:Github PK Tool

ionstorm's repositories

sentinel-attack

Repository of sentinel alerts and hunting queries leveraging sysmon and the MITRE ATT&CK framework

EDR-Testing-Script

Test the accuracy of Endpoint Detection and Response (EDR) software with simple script which executes various ATT&CK/LOLBAS/Invoke-CradleCrafter payloads

Language:BatchfileLicense:MITStargazers:2Issues:0Issues:0

ir-rescue

A Windows Batch script and a Unix Bash script to comprehensively collect host forensic data during incident response.

Language:BatchfileLicense:NOASSERTIONStargazers:2Issues:1Issues:0

IRCollect

Windows Incident Respose Script

Language:YARALicense:GPL-3.0Stargazers:2Issues:1Issues:0

KQL

KQL queries for Advanced Hunting

License:MITStargazers:2Issues:2Issues:0

Threat-Intel-Automation

Threat Intel Automation using Graylog and Critical-Stack-Intel

Language:PythonStargazers:2Issues:0Issues:0

Panache_Sysmon

Just another sysmon config

Stargazers:1Issues:0Issues:0

PowerShell-2

Collection of PowerShell Scripts

Language:PowerShellLicense:MITStargazers:1Issues:0Issues:0

SmartThingsPublic

SmartThings open-source DeviceTypeHandlers and SmartApps code

Language:GroovyStargazers:1Issues:0Issues:0

AnchorWatch

A Rogue Device Detection Script with Email Alerts Functionality for Windows Subsystem

Language:PowerShellLicense:GPL-3.0Stargazers:0Issues:1Issues:0

ansible-graylog-modules

Ansible modules for the Graylog API

Language:PythonLicense:GPL-3.0Stargazers:0Issues:2Issues:0

AZSentinel

PowerShell module for Azure Sentinel

Language:PowerShellLicense:MITStargazers:0Issues:1Issues:0

DLLSpy

DLL Hijacking Detection Tool

Language:C++License:LGPL-3.0Stargazers:0Issues:1Issues:0

elastalert_hive_alerter

This package allows the use of a custom Elastalert Alert which creates alerts with observables in TheHive using TheHive4Py.

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0

fpm-recipes

Graylog package build recipes

Language:ShellStargazers:0Issues:0Issues:0

graylog-plugin-alert-wizard

Alert Wizard plugin for Graylog to manage the alert rules

Language:JavaScriptLicense:GPL-3.0Stargazers:0Issues:0Issues:0

graylog-plugin-logging-alert

Alert notification plugin for Graylog to generate log messages from alerts

Language:JavaLicense:GPL-3.0Stargazers:0Issues:0Issues:0

graylog2thehive

Create alerts in The Hive from your Graylog alerts, to be turned into Hive cases.

Language:PythonStargazers:0Issues:2Issues:0
Language:PythonStargazers:0Issues:1Issues:0

influx_snmp

SNMP Data Collection and Analytics with the TICK Stack (Telegraf, InfluxDB, Chronograf and Kapacitor)

Language:DockerfileLicense:MITStargazers:0Issues:1Issues:0

Injection-McAfeeIDSAlerts-Graylog

Converts raw McAfee IDS alerts to Common event Format (CEF) compliant messages and finally injects into Graylog

Language:PythonStargazers:0Issues:0Issues:0

kirbogd-PHDays9

Presentation, queries and sample data from my talk at Positive Hack Days 2019

Language:PowerShellStargazers:0Issues:0Issues:0

lme

Logging Made Easy

Language:ShellLicense:Apache-2.0Stargazers:0Issues:0Issues:0

powershell-3

Miscellaneous powershell scripts

License:BSD-3-ClauseStargazers:0Issues:0Issues:0

ProcessReimaging

Process reimaging proof of concept code

Stargazers:0Issues:0Issues:0

PSGraylog

A powershell module for Graylog

Language:PowerShellLicense:MITStargazers:0Issues:1Issues:0
Language:HTMLStargazers:0Issues:0Issues:0
Language:C#License:NOASSERTIONStargazers:0Issues:0Issues:0

TA-windnsanalytical

Based on Jake Walter's Windows DNS Analytical Log App (https://splunkbase.splunk.com/app/2937/)

Language:PowerShellStargazers:0Issues:0Issues:0

velociraptor

Velociraptor hunts for evil...

Language:GoLicense:NOASSERTIONStargazers:0Issues:0Issues:0