
DShield-SIEM
DShield Sensor Log Collection with ELK

DShield Sensor Log Collection with ELK

GitHub mirror of the Linux Kernel's audit repository

Mapping Corelight or Zeek data to Elastic Common Schema logs

Mapping Corelight or Zeek data to Elastic Common Schema fields


Script to check for IOC's created by ProxyNotShell (CVE-2022-41040 & CVE-2022-41082)

This script is used to perform a fast check if your server is possibly affected by CVE-2021-44228 (the log4j vulnerability).

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

An Active Defense and EDR software to empower Blue Teams

Security event correlation engine for ELK stack

A python package for use in generating fake data for SOC and security automation.

Sysmon event simulation utility which can be used to simulate the attacks to generate the Sysmon Event logs for testing the EDR detections and…

Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

Artifact collection tool for *nix systems