
DShield-SIEM
DShield Sensor Log Collection with ELK
defensive-toolsincident-responseintrusion-detection+4
50

DShield Sensor Log Collection with ELK

Parse and analyze a Windows Amcache.hve registry hive, VirusTotal integration.

A python script that can detect and parse loki-bot (malware) related network traffic. This script can be helpful to DFIR analysts and security…

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

This is a repo for fetching Applocker event log by parsing the win-event log