
Ce projet est un SIEM avec SIRP et Threat Intel, le tout en un.

Pour un fichier EVTX, vous pouvez essayer S1EM (Zircolite) avec EVTX-ATTACK-SAMPLES.
Pour un fichier Pcap, vous pouvez essayer S1EM (Suricata/Zeek/Mwdb) avec MALWARE-TRAFFIC-ANALYSIS.
Le serveur Discord de S1EM : https://discord.gg/uFBzr8fWmC
https://www.elastic.co
https://github.com/TheHive-Project/Docker-Templates
https://github.com/jasonish/docker-suricata
https://github.com/blacktop/docker-zeek
https://github.com/rskntroot/arkime
https://github.com/coolacid/docker-misp
https://github.com/m0ns7er/ElasticXDR
https://github.com/jertel/elastalert-docker
https://github.com/OpenCTI-Platform/docker
https://github.com/CERT-Polska/mwdb-core
https://github.com/SigmaHQ/sigma
https://github.com/Yara-Rules/rules
https://traefik.io/
https://docs.linuxserver.io/images/docker-heimdall
https://github.com/cisagov/Malcolm
https://github.com/blueimp/jQuery-File-Upload
https://gchq.github.io/CyberChef/
https://www.syslog-ng.com/
https://github.com/bastienwirtz/homer
https://github.com/wagga40/zircolite
https://github.com/weslambert
https://github.com/Velocidex/velociraptor
En français cette fois.
Merci à mes amis et collègues qui m´ont inspiré toutes ces années, qui m´ont aidé, et corrigé des bugs.
Je pense à Kidrek, Juju, mlp1515, Wagga40, Xophidia, StevenDias33, Frak113, HiPizzaa,et tous ceux qui n´ont pas forcement de compte github.
Merci à vous :)
Liens github:
https://github.com/kidrek
https://github.com/mlp1515
https://github.com/frack113
https://github.com/StevenDias33
https://github.com/wagga40
https://github.com/xophidia
Merci à @Mcdave2k1 pour vos pull requests
Si ce projet vous aide à réduire le temps de développement, vous pouvez m'offrir un café :)