
pySigma-backend-opensearch
Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

Converts Sigma detection rules into OpenSearch Lucene and PPL queries, including alerting Monitor Rules and correlation support for SIEM detection…

The Sigma command line interface based on pySigma

Parses Apple Unified Logs to extract process, thread, activity, timestamp, and message metadata from logarchives or live macOS systems into JSONL/CSV…

Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic…

Generates and maintains Azure Sentinel parser for Sysmon events, normalizing all Windows endpoint telemetry into a searchable log schema via…

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

This project is 'bridge' between the sleep and python language. It allows the control of a Cobalt Strike teamserver through python without the need…

USB HID driver emulation with PID/VID (0x3bca/0x27bb) of Plenom A/S Busylight Alpha, that is supported by Mimikatz. When mimikatz is executed, a…

A collection of scripts for processing network forensics type data and intelligence, mainly into a postgres database.


A Simple Log4j Indicator of Compromise Linux Detector

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

Add POST body excerpt to Bro's HTTP log


This package extends the Intel package to log more fields

Corelight or Zeek Elastic Common Schema Templates

A high-speed forensic timeline engine for Windows forensic artifact CSV output built for DFIR investigators. Quickly consolidate CSV output from…

Audit Preference Pane and Log Reader for OS X