
plaso
Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Audit Preference Pane and Log Reader for OS X

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

A curated knowledge base to build, run and mature a SOC (including CSIRT).