
pySigma-backend-opensearch
Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

The Sigma command line interface based on pySigma

Hunts for potential malware downloads and suspicious domain calls via common Windows LOLBins using YARA rules and Nexthink telemetry modules.

Rules generated from our investigations.

Rapidly Search and Hunt through Windows Forensic Artefacts

Just a git repo for the sleepmask detection rule i found in https://codex-7.gitbook.io/codexs-terminal-window/blue-team/detecting-cobalt-strike/sleep-…

Docker configuration to quickly setup your own Canarytokens.

A continuously updated collection of threat intelligence indicators of compromise (IOCs), including YARA rules, for detecting and tracking malware…

A repository of sysmon configuration modules

A simple binary wrapper for DNS canarytokens.

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Detect Tactics, Techniques & Combat Threats

Multi-engine Linux malware scanner with five detection stages (MD5, HEX pattern, YARA, ClamAV, statistical), real-time inotify monitoring,…

Documentation and scripts to properly enable Windows event logs.

Production-ready detection & response queries for osquery

A repository of my own Sigma detection rules.

Collection of private Yara rules.