
ecs-logstash-mappings
Mapping Corelight or Zeek data to Elastic Common Schema logs
incident-responseintrusion-detectionlog-analysis+2
11

Mapping Corelight or Zeek data to Elastic Common Schema logs

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

This repository demonstrates a machine learning pipeline for detecting MITRE ATT&CK techniques from logs and enriching the output using a local LLM.

