
如今,网络攻击愈发频繁,给企业造成损失。尽管如此,市面上已有许多用于检测网络威胁的软件产品。S1EM 解决方案基于这样一个原则:汇聚各自领域内最佳的免费产品,并使其快速实现互操作。
S1EM 是一款集 SIEM、SIRP 和威胁情报于一体的完整数据包捕获解决方案。
解决方案包含:

对于 EVTX 文件,您可以使用 EVTX-ATTACK-SAMPLES 来试用 S1EM (Zircolite)。
对于 Pcap 文件,您可以使用 MALWARE-TRAFFIC-ANALYSIS 来试用 S1EM (Suricata/Zeek/Mwdb)。
S1EM 的 Discord 服务器:https://discord.gg/uFBzr8fWmC
https://www.elastic.co
https://github.com/TheHive-Project/Docker-Templates
https://github.com/jasonish/docker-suricata
https://github.com/blacktop/docker-zeek
https://github.com/rskntroot/arkime
https://github.com/coolacid/docker-misp
https://github.com/m0ns7er/ElasticXDR
https://github.com/jertel/elastalert-docker
https://github.com/OpenCTI-Platform/docker
https://github.com/CERT-Polska/mwdb-core
https://github.com/SigmaHQ/sigma
https://github.com/Yara-Rules/rules
https://traefik.io/
https://docs.linuxserver.io/images/docker-heimdall
https://github.com/cisagov/Malcolm
https://github.com/blueimp/jQuery-File-Upload
https://gchq.github.io/CyberChef/
https://www.syslog-ng.com/
https://github.com/bastienwirtz/homer
https://github.com/wagga40/zircolite
https://github.com/weslambert
https://github.com/Velocidex/velociraptor
这次用法语。
感谢多年来启发、帮助并为我修正错误的朋友和同事们。我特别想到 Kidrek、Juju、mlp1515、Wagga40、Xophidia、StevenDias33、Frak113、HiPizzaa,以及所有不一定有 GitHub 账户的人。
谢谢你们 :)
GitHub 链接:
https://github.com/kidrek
https://github.com/mlp1515
https://github.com/frack113
https://github.com/StevenDias33
https://github.com/wagga40
https://github.com/xophidia
感谢 @Mcdave2k1 的拉取请求
如果这个项目帮助您减少了开发时间,您可以请我喝杯咖啡 :)