-
-
-
sigma-rust Public
Forked from jopohl/sigma-rustA Rust library for parsing and evaluating Sigma rules
Rust Apache License 2.0 UpdatedJan 18, 2025 -
jve Public
Cmd line utility that accepts json via standard in (piping) and extracts values from json fields.
-
-
-
-
-
sysmon Public
Sysmon custom configs (template from SwitchOnSecurity)
-
Linux_Forensic_Harvester Public
Harvest Linux forensic data for operational triage of an event.
-
sigma_to_wazuh Public
Convert Sigma rules to Wazuh rules
-
vyos-1x Public
Forked from vyos/vyos-1xVyOS command definitions, scripts, and utilities
Python GNU Lesser General Public License v2.1 UpdatedApr 9, 2024 -
-
-
reg_hunter Public
Blueteam operational triage registry hunting/forensic tool.
-
log_sieve Public
External elastic / opensearch log alerting tool
Rust MIT License UpdatedApr 30, 2023 -
lnk-rs Public
Forked from lilopkins/lnk-rsA Rust library for parsing and writing MS Shell Links (shortcuts, *.lnk)
Rust UpdatedFeb 24, 2023 -
OS-defaults_research Public
Information pertaining to OS install defaults to baseline normal for a given OS.
-
-
sigma Public
Forked from SigmaHQ/sigmaGeneric Signature Format for SIEM Systems
Python UpdatedApr 9, 2021 -
iTerm2-Color-Schemes Public
Forked from mbadolato/iTerm2-Color-SchemesOver 230 terminal color schemes/themes for iTerm/iTerm2. Includes ports to Terminal, Konsole, PuTTY, Xresources, XRDB, Remmina, Termite, XFCE, Tilda, FreeBSD VT, Terminator, Kitty, MobaXterm, LXTer…
Shell Other UpdatedFeb 26, 2021 -
wazuh Public
Forked from wazuh/wazuhWazuh - The Open Source Security Platform
C Other UpdatedFeb 23, 2021 -
Evil_DLL Public
Simple DLL to test various injection methods.
-
HOWTO-Elastic_Scroll_API Public
Example how to use the Elastic Scroll API to pull back more than the default max of 10k logs.
UpdatedSep 25, 2019 -
Ultimate-Forensics-VM Public
Evolving directions on building the best Open Source Forensics VM
-
-
-
securityonion-elsa-extras Public
Forked from Security-Onion-Solutions/securityonion-elsa-extrasShell UpdatedJan 30, 2017 -
Kansa Public
Forked from davehull/KansaA Powershell incident response framework
PowerShell Apache License 2.0 UpdatedDec 16, 2016 -
packages Public
Forked from zeek/packagesThe default package source of the Bro Package Manager: https://github.com/bro/package-manager
UpdatedNov 1, 2016