
DeepBlueCLI
PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…
digital-forensicsincident-responseintrusion-detection+2
2.4k

PowerShell-based threat hunting tool that analyzes Windows Event Logs to detect malicious activity including credential attacks, obfuscated commands,…

This tool parses log data and allows to define analysis pipelines for anomaly detection. It was designed to run the analysis with limited resources…

Corelight@Home script

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)