
ad-honeypot-autodeploy
Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Deploy a small, intentionally insecure, vulnerable Windows Domain for RDP Honeypot fully automatically.

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM


The Sigma command line interface based on pySigma

eBPF-powered Linux observability with AI incident detection. AGPL-3.0 licensed.

A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from…

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

Sigma rules from Joe Security

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

Query high-fidelity cloud detections for known threat actors across AWS, Azure, and GCP using CloudTrail logs and custom threat intelligence rules.

Flows-first PCAP TUI (case files, gorgeous UX). Do do do do.

Incident Response collection and processing scripts with automated reporting scripts

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI

Implementation of RITA (Real Intelligence Threat Analytics) in Jupyter Notebook with improved scoring algorithm.

CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. All queries stored here are…

A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.

Parses Snaffler output file and generate beautified outputs.