secops4thewin's repositories

TA-intezer

This app leverages the Adaptive Response framework to search against the intezer analyze APIs

Language:PythonLicense:MITStargazers:17Issues:1Issues:1

TA-securitytrails

This app leverages the Adaptive Response framework to perform API calls to Security Trails

Language:PythonLicense:MITStargazers:14Issues:3Issues:0

securitytrails-python

Python 2.7 wrapper for the securitytrails api.

Language:PythonLicense:GPL-3.0Stargazers:12Issues:1Issues:0

force_directed_viz

D3 Force Directed visualization for Splunk.

Language:JavaScriptStargazers:6Issues:1Issues:1

link_analysis_app

Link Analysis App for Splunk.

Language:JavaScriptLicense:MITStargazers:4Issues:0Issues:0

phthreatminer

This github repo will house the Phantom Cyber app for Threat Miner

Language:PythonLicense:MITStargazers:3Issues:0Issues:0

UiPath-RPAMacroSigning

This project is a file that runs you through the process of automatically signing office files

License:MITStargazers:3Issues:0Issues:1

phintezeranalyze

Phantom Cyber App for Intezer Analyze. https://analyze.intezer.com/

Language:PythonLicense:GPL-3.0Stargazers:2Issues:0Issues:0

phipinfo

This is the Phantom Cyber app for IP Info

Language:PythonLicense:Apache-2.0Stargazers:2Issues:0Issues:0

devoDetections

Mitre Att&ck Navigator layout for Devo

AustralianKMZFiles

A repo to host KMZ files for use in visualization apps.

License:MITStargazers:0Issues:0Issues:0

canary_app

This app is used to visualise data generated from Canary Tools Devices.

License:GPL-3.0Stargazers:0Issues:0Issues:0

data_generator

Using Gogen from coccyx

Language:ShellStargazers:0Issues:0Issues:0

detection-rules

Rules for Elastic Security's detection engine

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0
Language:ShellLicense:MITStargazers:0Issues:0Issues:0

devoRsyslogConfigurations

A repo to store rsyslog configuration for automation purposes

Stargazers:0Issues:1Issues:0

docker-domain_stats

This github repo holds a Dockerfile to automatically build Mark Baggets Domain Stats python server. https://github.com/MarkBaggett/domain_stats/tree/master/domain_stats

Language:DockerfileLicense:MITStargazers:0Issues:0Issues:0

ecs

Elastic Common Schema

Language:PythonLicense:Apache-2.0Stargazers:0Issues:0Issues:0
Language:PowerShellLicense:GPL-3.0Stargazers:0Issues:0Issues:0

gogen

Highly configurable and scalable data generator for testing or demo data

Language:GoStargazers:0Issues:0Issues:0

mitreAttackDetectionsByDataSource

Shows Detections by Mitre Data Source

Stargazers:0Issues:0Issues:0

phairlockdigital

Phantom App For Airlock Digital

Language:PythonLicense:MITStargazers:0Issues:0Issues:0

security-ws-labs

Elastic Security Workshop Labs

Stargazers:0Issues:0Issues:0

sigma

Generic Signature Format for SIEM Systems

Language:PythonLicense:NOASSERTIONStargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

TA-ipv6-search

This app creates a custom search command in Splunk to search ipv6 ranges

Language:PythonLicense:MITStargazers:0Issues:1Issues:0

TA-javelin-protect

This add-on provides parsing configuration for Javelin Protect https://www.javelin-networks.com/

Language:PythonLicense:MITStargazers:0Issues:0Issues:0

TA-search_splunk

This app leverages the Adaptive Response framework to allow searches to be issued automatically.

Language:PythonLicense:GPL-3.0Stargazers:0Issues:2Issues:0

TA_autoruns

This Splunk Add-On runs autoruns command line edition and parses the data ready for use in Splunk

Language:BatchfileStargazers:0Issues:0Issues:0