tuckner's repositories

automation-capability-matrix

A tool that allows you to document and assess any security automation in your SOC

Language:TypeScriptLicense:MITStargazers:35Issues:2Issues:1

detection-rules

Rules for Elastic Security's detection engine

Language:PythonLicense:NOASSERTIONStargazers:7Issues:0Issues:0

dsmap

Mapping for data sources to visibility files for the DeTT&CT project

Language:PythonLicense:MITStargazers:5Issues:1Issues:0

acm-soc

The SOC Automation Capability Matrix

License:MITStargazers:3Issues:0Issues:0

cuckoo-bot

Simple Slack bot to submit hashes to a Cuckoo Sandbox instance

Language:PythonLicense:GPL-3.0Stargazers:3Issues:2Issues:0

attack-navigator-layers

Collection of ATT&CK research with ATTT&CK Navigator layers

License:GPL-3.0Stargazers:2Issues:2Issues:0

tines-example-stories

A collection of Tines example stories as export files and Terraform.

Language:HCLStargazers:2Issues:2Issues:0

ansible-art

Action Plugin for Ansible as an execution framework for Atomic Red Team by Red Canary

Language:PythonLicense:GPL-3.0Stargazers:1Issues:2Issues:0

bolt-docker

A container that runs Slack Bolt to receive message events and send to a webhook

Language:PythonLicense:MITStargazers:1Issues:0Issues:0

netwitness-urlscan

Context Menu for RSA NetWitness to search for a domain on urlscan.io

License:GPL-3.0Stargazers:1Issues:2Issues:0

python-tines

Tines API Wrapper

Language:PythonLicense:MITStargazers:1Issues:2Issues:0

tines-connect

ngrok container to use with Tines

vagrant-check-point

Vagrantfile for turning up Check Point firewall lab environments

Language:ShellLicense:MITStargazers:1Issues:2Issues:0

ansible

Ansible is a radically simple IT automation platform that makes your applications and systems easier to deploy. Avoid writing scripts or custom code to deploy and update your applications— automate in a language that approaches plain English, using SSH, with no agents to install on remote systems.

Language:PythonLicense:GPL-3.0Stargazers:0Issues:2Issues:0
Stargazers:0Issues:0Issues:0

atc-react

A knowledge base of actionable Incident Response techniques

License:Apache-2.0Stargazers:0Issues:0Issues:0

atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

Language:PowerShellLicense:MITStargazers:0Issues:1Issues:0

awesome-detection-engineering

A list of useful Detection Engineering-related resources.

License:CC0-1.0Stargazers:0Issues:0Issues:0
Stargazers:0Issues:0Issues:0

EVTX-ATTACK-SAMPLES

Windows Events Samples

Language:PowerShellStargazers:0Issues:1Issues:0

presentations

Resources and recordings for various presentations

Stargazers:0Issues:0Issues:0

quickstart-snyk-security

AWS Quick Start Team

License:Apache-2.0Stargazers:0Issues:0Issues:0
License:Apache-2.0Stargazers:0Issues:0Issues:0
Language:PythonStargazers:0Issues:0Issues:0

sigma

Generic Signature Format for SIEM Systems

Language:PythonStargazers:0Issues:1Issues:0

Sooty

The SOC Analysts all-in-one CLI tool to automate and speed up workflow.

Language:PythonLicense:GPL-3.0Stargazers:0Issues:0Issues:0

tines-deploy-actions

An example of how to deploy Tines stories using Github Actions and Terraform

Language:HCLStargazers:0Issues:0Issues:0
License:MITStargazers:0Issues:2Issues:0
Stargazers:0Issues:0Issues:0

webhook-plugin

A Chrome plugin which creates a context menu to send a page's URL and contents to a webhook

Language:JavaScriptStargazers:0Issues:0Issues:0