
raspi-corelight
Corelight@Home script

Corelight@Home script

Step-by-step guide for hardening a Linux server, covering SSH security, firewalls, intrusion detection, auditing, and system configuration to reduce…

Open-source XDR and SIEM platform for threat detection, log analysis, file integrity monitoring, vulnerability assessment, and compliance management…

Mail-in-a-Box helps individuals take back control of their email by defining a one-click, easy-to-deploy SMTP+everything else server: a mail server…

Centralized network visibility and continuous asset discovery. Monitor devices, detect change, and stay aware across distributed networks.

Automate the creation of a lab environment complete with security tooling and logging best practices

Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and serverless. It…

A Linux Auditd rule set mapped to MITRE's Attack Framework

Best Practice Auditd Configuration

Pulled Pork for Snort and Suricata rule management (from Google code)

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Documentation and scripts to properly enable Windows event logs.

Production-ready detection & response queries for osquery

An ADCS honeypot to catch attackers in your internal network.

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM

Blue Team detection lab created with Terraform and Ansible in Azure.

Centralize or distribute IPset blacklists

PowerShell-based security toolkit for small-to-medium enterprises, providing automated alerts, Active Directory hardening, Windows Event Forwarding,…