
plaso
Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

Digital forensics engine that parses logs, files, and system artifacts to build super timelines, enabling chronological event correlation for…

A curated knowledge base to build, run and mature a SOC (including CSIRT).

Turn Rootly incidents, alerts, and teams into a queryable knowledge graph. Visualize service dependencies, on-call coverage gaps, and cross-incident…

Community Detection Signature Build and Distribution Pipeline for YARA, Suricata, Snort and Sigma

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI

Audit Preference Pane and Log Reader for OS X