
이 프로젝트는 SIEM, SIRP 및 Threat Intel을 모두 포함하는 올인원 솔루션입니다.

EVTX 파일의 경우 EVTX-ATTACK-SAMPLES로 S1EM(Zircolite)을 사용해 볼 수 있습니다.
Pcap 파일의 경우 MALWARE-TRAFFIC-ANALYSIS로 S1EM(Suricata/Zeek/Mwdb)을 사용해 볼 수 있습니다.
S1EM 디스코드 서버: https://discord.gg/uFBzr8fWmC
https://www.elastic.co
https://github.com/TheHive-Project/Docker-Templates
https://github.com/jasonish/docker-suricata
https://github.com/blacktop/docker-zeek
https://github.com/rskntroot/arkime
https://github.com/coolacid/docker-misp
https://github.com/m0ns7er/ElasticXDR
https://github.com/jertel/elastalert-docker
https://github.com/OpenCTI-Platform/docker
https://github.com/CERT-Polska/mwdb-core
https://github.com/SigmaHQ/sigma
https://github.com/Yara-Rules/rules
https://traefik.io/
https://docs.linuxserver.io/images/docker-heimdall
https://github.com/cisagov/Malcolm
https://github.com/blueimp/jQuery-File-Upload
https://gchq.github.io/CyberChef/
https://www.syslog-ng.com/
https://github.com/bastienwirtz/homer
https://github.com/wagga40/zircolite
https://github.com/weslambert
https://github.com/Velocidex/velociraptor
이번에는 프랑스어로 감사 인사를 드립니다.
지난 수년간 저에게 영감을 주고, 도움을 주며 버그를 수정해 준 친구들과 동료들에게 감사드립니다.
Kidrek, Juju, mlp1515, Wagga40, Xophidia, StevenDias33, Frak113, HiPizzaa, 그리고 github 계정이 없는 모든 분들께 감사드립니다.
감사합니다 :)
Github 링크:
https://github.com/kidrek
https://github.com/mlp1515
https://github.com/frack113
https://github.com/StevenDias33
https://github.com/wagga40
https://github.com/xophidia
@Mcdave2k1님의 pull request에 감사드립니다.
이 프로젝트가 개발 시간을 단축하는 데 도움이 되셨다면, 커피 한 잔 사주세요 :)