
ecs-logstash-mappings
Mapping Corelight or Zeek data to Elastic Common Schema logs

Mapping Corelight or Zeek data to Elastic Common Schema logs

HonSSH is designed to log all SSH communications between a client and server.

E-mails, subdomains and names Harvester - OSINT

Automated BloodHound graph updater for blue teams. Enriches AD attack paths with real-time session, group, and CVE data from SIEMs, enabling…

Security event correlation engine for ELK stack

Artifact collection tool for *nix systems

DShield Sensor Log Collection with ELK

A repository that maps commonly used attacks using MSRPC protocols to ATT&CK

Recognizing the most likely APT groups responsible for an incident

I-SOON/Anxun leak related stuff


Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders

🔍 A simple Bash script to detect malicious JSP webshells, including those used in exploits of SAP NetWeaver CVE-2025-31324.

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Repository created to share information about tactics, techniques and procedures used by threat actors. Initially with ransomware groups and evolving…

Tool to predict attacker groups from the techniques and software used

Botnet command & control monitor