There are 6 repositories under security-operations topic.
学习安全运营的记录 | The knowledge base of security operation
Reconmap is a collaboration-first security operations platform for infosec teams and MSSPs, enabling end‑to‑end engagement management, from reconnaissance through execution and reporting. With built-in command automation, output parsing, and AI‑assisted summaries, it delivers faster, more structured, and high‑quality security assessments.
Community Security Analytics provides a set of community-driven audit & threat queries for Google Cloud
Detecting ATT&CK techniques & tactics for Linux
Open-source framework to detect outliers in Elasticsearch events
Pointing cybersecurity teams to thousands of detection rules and offensive security tests aligned with common attacker techniques
MCP Server for Wazuh SIEM
Curso para aprender Ciberseguridad desde cero, en español y 100% gratis. Abarca 5 dominios fundamentales que necesitas conocer para poder dar tus primeros pasos en este apasionante mundo.
My learning, tutorials on Cybersecurity
Write detections, investigate alerts, and query logs from your favorite AI agents
Elastic TIP is a python tool which automates the process of aggregating Threat Intelligence and ingesting the intelligence into a common format into Elasticsearch with the main goal of being used by the Security solution.
:bar_chart: Deploy an "illegal" SOC to manage vulnerabilities on your city servers in minutes.
A Security Operations playbook to assist blue teamers from day-to-day tasks to Digital Forensics and Incident Response (DFIR) activities.
An Elasticsearch Beat to monitor DNS zones through customizable zone transfers.
A curated collection of essential resources, tools, and references for Security Operations Center (SOC) analysts.
Interviewing Help for Information Security Jobs (With Answers)
Intelligent SOC automation framework powered by LangGraph multi-agent workflows for alert triage, correlation, and incident response
A user-friendly and powerful tool to analyze Windows Security Events
A comprehensive integration solution connecting MISP threat intelligence with Wazuh security monitoring for real-time threat detection. This project provides step-by-step instructions for deploying, configuring, and integrating MISP and Wazuh with Sysmon to automatically detect indicators of compromise (IoCs) in your environment.
🛡️⚔️ Curated GitHub repos for Defensive & Offensive Cyber Tradecraft
Visual analytics using Databricks & Graphistry for cybersecurity investigations
This is a cybersecurity certification that proves that an individual have the fundamental knowledge, skills and ability for an entry-level or junior-level cybersecurity role. It is ANAB accredited, ISO/IEC STANDARD 17024.
Takes a Onion URL and Hashes it and compares it against blacklisted hashed onion URLS
Enterprise Azure security architecture with multi-domain implementation covering identity, network, compute, and security operations
# Defensive Security Hub A curated collection of essential resources, tools, and references for Security Operations Center (SOC) analysts. This repository aims to support your security efforts and enhance your skills. 🌐🔒
Introduction to SOC and related terminologies.
Centralized AWS security monitoring lab using CloudTrail, CloudWatch, and Athena to detect root account usage and unauthorized API calls. Includes saved queries, dashboards and threat-hunting examples.
Splunk case manager
A list of free or open source tools or resources that have proven useful over the years.
A list of free cybersecurity tools with links. Creating this for my own reference. These tools are separated by category that would typically be seen in a SOC.
Executive phishing email analysis for VitalCare Health Solutions – includes header inspection, BEC indicators, SPF/DKIM/DMARC checks, malicious attachment & URL analysis, and a stakeholder-ready executive report with findings, impact, and recommendations.
Simulated SOC ticketing workflow using Jira and serviceNow for phishing, Malware, And login alert investigations.