
Dieses Projekt ist ein SIEM mit SIRP und Threat Intel, alles in einem.

Für EVTX-Dateien können Sie S1EM (Zircolite) mit EVTX-ATTACK-SAMPLES ausprobieren.
Für Pcap-Dateien können Sie S1EM (Suricata/Zeek/Mwdb) mit MALWARE-TRAFFIC-ANALYSIS ausprobieren.
Der Discord-Server von S1EM: https://discord.gg/uFBzr8fWmC
https://www.elastic.co
https://github.com/TheHive-Project/Docker-Templates
https://github.com/jasonish/docker-suricata
https://github.com/blacktop/docker-zeek
https://github.com/rskntroot/arkime
https://github.com/coolacid/docker-misp
https://github.com/m0ns7er/ElasticXDR
https://github.com/jertel/elastalert-docker
https://github.com/OpenCTI-Platform/docker
https://github.com/CERT-Polska/mwdb-core
https://github.com/SigmaHQ/sigma
https://github.com/Yara-Rules/rules
https://traefik.io/
https://docs.linuxserver.io/images/docker-heimdall
https://github.com/cisagov/Malcolm
https://github.com/blueimp/jQuery-File-Upload
https://gchq.github.io/CyberChef/
https://www.syslog-ng.com/
https://github.com/bastienwirtz/homer
https://github.com/wagga40/zircolite
https://github.com/weslambert
https://github.com/Velocidex/velociraptor
Auf Französisch diesmal.
Merci à mes amis et collègues qui m´ont inspiré toutes ces années, qui m´ont aidé, et corrigé des bugs.
Je pense à Kidrek, Juju, mlp1515, Wagga40, Xophidia, StevenDias33, Frak113, HiPizzaa,et tous ceux qui n´ont pas forcement de compte github.
Merci à vous :)
Liens github:
https://github.com/kidrek
https://github.com/mlp1515
https://github.com/frack113
https://github.com/StevenDias33
https://github.com/wagga40
https://github.com/xophidia
Danke an @Mcdave2k1 für Ihre Pull-Requests
Wenn dieses Projekt Ihnen hilft, Entwicklungszeit zu sparen, können Sie mir einen Kaffee spendieren :)