
DShield-SIEM
DShield Sensor Log Collection with ELK

DShield Sensor Log Collection with ELK

Automatically generated Sysmon parser for Azure Sentinel

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

A Zeek OpenVPN protocol analyzer plugin.

Bro analyzer that detects Google's QUIC protocol

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

This is a repo for fetching Applocker event log by parsing the win-event log

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…