Repository navigation

#

siem

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

Python
2447
3 个月前

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

Python
2168
3 年前
sherifabdlnaby/elastdocker

🐳 Elastic Stack (ELK) v8+ on Docker with Compose. Pre-configured out of the box to enable Logging, Metrics, APM, Alerting, ML, and SIEM features. Up with a Single Command.

Dockerfile
1871
4 个月前
matanolabs/matano
Rust
1550
3 个月前

A collection of sources of documentation, as well as field best practices, to build/run a SOC

1364
2 个月前
pfelk/pfelk
Shell
1119
3 个月前
netevert/sentinel-attack

Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK

HCL
1067
5 个月前

A collective list of public APIs for use in security. Contributions welcome

918
2 天前

Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsacyber

PowerShell
864
4 年前

Transform Linux Audit logs for SIEM usage

Rust
761
21 天前

A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-183b7df7a2f4

Python
564
1 个月前