
Azure-Sentinel
Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. All queries stored here are…


This project aims to compare and evaluate the telemetry of various EDR products.

A curated portfolio showcasing my SOC investigations, threat hunting projects, DFIR labs, detection engineering, technical blogs, and cybersecurity…

A repo to hold KQL queries as part of my 100 days of KQL effort.

Content packs for Eventum

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM

This repository contains a list of new remediation scripts.

A tool to assess data quality, built on top of the awesome OSSEM.

This repository contains validated detection rules for adversary behaviors observed during APT29 simulation. Each rule was tested against the actual…

Rules generated from our investigations.

The Sigma command line interface based on pySigma

TrustedSec Sysinternals Sysmon Community Guide

A curated collection of DFIR skills and workflows for InfoSec practitioners.

Cyber Threat Defense World Modeling

Sigma Rule for CVE-2025-49666

Free, offline SOC Analyst Hub for Tier 1 — IR checklists, alert triage playbooks, threat hunting queries & analyst onboarding. Single HTML file, no…