
crowdstrike-falcon-queries
A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Offline-first network investigation and response platform for Windows. Turns a pcap or live capture into a full forensic verdict — attack story,…

Detection of Manjusaka C2 framework

Detect Tactics, Techniques & Combat Threats

Sysmon configuration file template with default high-quality event tracing

Apache Real Time Logs Analyzer System

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Mapping Corelight or Zeek data to Elastic Common Schema logs

Zeek package that detects CVE-2022-22954 exploit attempts, logs exploit URIs and attacker response data to aid in incident response and network…

Collection of private Yara rules.

A collection of Tools and Rules for decoding Brute Ratel C4 badgers

A collection of IOCs for CVE-2021-44228 also known as Log4Shell

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

Curated collection of detection rules and IOCs extracted from DFIR engagements and malware analyses to support threat hunting, incident response, and…

Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, Suricata and…


Defensive detection package for CVE-2026-31431 (Linux kernel AF_ALG LPE). Sigma, Falco, auditd, KQL, and EQL rules mapped to MITRE ATT&CK…