
threat-intel
Signatures and IoCs from public Volexity blog posts.

Signatures and IoCs from public Volexity blog posts.

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

Rules generated from our investigations.

Aggregated Zeek-format threat intelligence feeds with combined indicators from public and curated sources for continuous IDS and network threat…

Sigma rules from Joe Security

Slides and materials from conference presentations

Slides from various conference talks

Open-source network IDS/IPS/NSM engine for real-time traffic inspection, intrusion detection and prevention, protocol analysis, and rule-based threat…

The Console Monitor Driver is a KMDF kernel-mode filter driver that captures certain Fast I/O operations (input and output) that is sent to or from…

Royal APT - APT15 - Related Information from NCC Group Cyber Defense Operations Research

Generate bulk YARA rules from YAML input

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Fingerprint SSH clients and servers.


Corelight@Home script

A Zeek OpenVPN protocol analyzer, based on Spicy.

Mapping Corelight or Zeek data to Elastic Common Schema logs