
هذا المشروع هو SIEM مع SIRP و Threat Intel، كل ذلك في واحد.

بالنسبة لملفات EVTX، يمكنك تجربة S1EM (Zircolite) مع EVTX-ATTACK-SAMPLES.
بالنسبة لملفات Pcap، يمكنك تجربة S1EM (Suricata/Zeek/Mwdb) مع MALWARE-TRAFFIC-ANALYSIS.
سيرفر ديسكورد لـ S1EM : https://discord.gg/uFBzr8fWmC
https://www.elastic.co
https://github.com/TheHive-Project/Docker-Templates
https://github.com/jasonish/docker-suricata
https://github.com/blacktop/docker-zeek
https://github.com/rskntroot/arkime
https://github.com/coolacid/docker-misp
https://github.com/m0ns7er/ElasticXDR
https://github.com/jertel/elastalert-docker
https://github.com/OpenCTI-Platform/docker
https://github.com/CERT-Polska/mwdb-core
https://github.com/SigmaHQ/sigma
https://github.com/Yara-Rules/rules
https://traefik.io/
https://docs.linuxserver.io/images/docker-heimdall
https://github.com/cisagov/Malcolm
https://github.com/blueimp/jQuery-File-Upload
https://gchq.github.io/CyberChef/
https://www.syslog-ng.com/
https://github.com/bastienwirtz/homer
https://github.com/wagga40/zircolite
https://github.com/weslambert
https://github.com/Velocidex/velociraptor
بالفرنسية هذه المرة.
شكرًا لأصدقائي وزملائي الذين ألهموني طوال هذه السنوات، وساعدوني، وصححوا لي الأخطاء.
أفكر في Kidrek، Juju، mlp1515، Wagga40، Xophidia، StevenDias33، Frak113، HiPizzaa، وكل من ليس لديه بالضرورة حساب GitHub.
شكرًا لكم :)
روابط GitHub:
https://github.com/kidrek
https://github.com/mlp1515
https://github.com/frack113
https://github.com/StevenDias33
https://github.com/wagga40
https://github.com/xophidia
شكرًا لـ @Mcdave2k1 على طلبات السحب الخاصة بك
إذا ساعدك هذا المشروع في تقليل وقت التطوير، يمكنك أن تقدم لي فنجانًا من القهوة :)