
このプロジェクトは、SIEM、SIRP、Threat Intelをすべて統合したものです。

今日、サイバー攻撃はますます増加し、企業に損害をもたらしています。それでも、サイバー脅威を検出するための多くのソフトウェア製品が存在します。S1EMソリューションは、それぞれの分野で最高の製品を無料で統合し、迅速に相互運用可能にするという原則に基づいています。
S1EMは、SIRPとThreat Intelを備えたSIEMであり、フルパケットキャプチャをすべて1つにまとめたものです。
ソリューションの内部構成:

EVTXファイルの場合、EVTX-ATTACK-SAMPLES を使ってS1EM(Zircolite)をお試しいただけます。
Pcapファイルの場合は、MALWARE-TRAFFIC-ANALYSIS を使ってS1EM(Suricata/Zeek/Mwdb)をお試しいただけます。
S1EMのDiscordサーバー: https://discord.gg/uFBzr8fWmC
https://www.elastic.co
https://github.com/TheHive-Project/Docker-Templates
https://github.com/jasonish/docker-suricata
https://github.com/blacktop/docker-zeek
https://github.com/rskntroot/arkime
https://github.com/coolacid/docker-misp
https://github.com/m0ns7er/ElasticXDR
https://github.com/jertel/elastalert-docker
https://github.com/OpenCTI-Platform/docker
https://github.com/CERT-Polska/mwdb-core
https://github.com/SigmaHQ/sigma
https://github.com/Yara-Rules/rules
https://traefik.io/
https://docs.linuxserver.io/images/docker-heimdall
https://github.com/cisagov/Malcolm
https://github.com/blueimp/jQuery-File-Upload
https://gchq.github.io/CyberChef/
https://www.syslog-ng.com/
https://github.com/bastienwirtz/homer
https://github.com/wagga40/zircolite
https://github.com/weslambert
https://github.com/Velocidex/velociraptor
今回はフランス語で。
長年にわたり私にインスピレーションを与え、助け、バグを修正してくれた友人や同僚に感謝します。
Kidrek、Juju、mlp1515、Wagga40、Xophidia、StevenDias33、Frak113、HiPizzaa、そして必ずしもGitHubアカウントを持っているわけではないすべての人々に感謝します。
ありがとうございます :)
GitHubリンク:
https://github.com/kidrek
https://github.com/mlp1515
https://github.com/frack113
https://github.com/StevenDias33
https://github.com/wagga40
https://github.com/xophidia
@Mcdave2k1さん、プルリクエストをありがとうございます。
このプロジェクトが開発時間を短縮するのに役立つなら、コーヒー1杯分をご寄付いただけると嬉しいです :)