
freedomfighting
A collection of scripts which may come in handy during your freedom fighting activities.

A collection of scripts which may come in handy during your freedom fighting activities.

DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

SO-CRATES: Security Onion Containerized Rapid Analysis of Threats, Evil, and Sus!

Awesome list of keywords and artifacts for Threat Hunting sessions

A curated collection of DFIR skills and workflows for InfoSec practitioners.

GitHub mirror of the Linux Kernel's audit repository

🛡️Awesome lists about all kinds of interesting topics of Wazuh XDR/SIEM

A collection of Splunk's Search Processing Language (SPL) for Threat Hunting with CrowdStrike Falcon

CQL Hub is an open repository of detection and hunting queries for CrowdStrike NextGen SIEM and Falcon LogScale. All queries stored here are…

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK…

A tool to assess data quality, built on top of the awesome OSSEM.

Fork of the AT Protocol reference implementation with performance-optimized AppView, Rust-based firehose indexer, Redis caching, and community…

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR

A repo to hold KQL queries as part of my 100 days of KQL effort.

The Intelligent Process Lifecycle of Active Cyber Defenders

Elastic version of SOC prime watcher rules

Advanced detection of port scanning, DoS and malware attacks using Machine Learning techniques

A Bro package to identify connections that are bursting (lots of data and transferring quickly).