Free and open source log management
-
Updated
Dec 10, 2022 - Java
Free and open source log management
Generic Signature Format for SIEM Systems
DEPRECATED - MozDef: Mozilla Enterprise Defense Platform
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.
Nzyme is a free and open next-generation WiFi defense system. Go to www.nzyme.org for more information.
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
pfSense/OPNsense + Elastic Stack
A collective list of public APIs for use in security. Contributions welcome
Advanced Sysmon ATT&CK configuration focusing on Detecting the Most Techniques per Data source in MITRE ATT&CK, Provide Visibility into Forensic Artifact Events for UEBA, Detect Exploitation events with wide CVE Coverage, and Risk Scoring of CVE, UEBA, Forensic, and MITRE ATT&CK Events.
Set of EVTX samples (>270) mapped to MITRE Att@k tactic and techniques to measure your SIEM coverage or developed new use cases.
A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework
A little tool to play with Azure Identity - Azure Active Directory lab creation tool
Encyclopedia for Executables
A robust, and flexible open source User & Entity Behavior Analytics (UEBA) framework used for Security Analytics. Developed with luv by Data Scientists & Security Analysts from the Cyber Security Industry. [PRE-ALPHA]
Add a description, image, and links to the siem topic page so that developers can more easily learn about it.
To associate your repository with the siem topic, visit your repo's landing page and select "manage topics."