All Projects → shadawck → awesome-endpoint-detection-and-response

shadawck / awesome-endpoint-detection-and-response

Licence: CC-BY-4.0 license
Collection of tool you need to have in your Endpoint Detection and Response arsenal

Projects that are alternatives of or similar to awesome-endpoint-detection-and-response

agent
This repository includes source codes for Nanny-I for Linux. We're pleased you to join our project.
Stars: ✭ 13 (-51.85%)
Mutual labels:  endpoint-protection, endpoint-security
Rhythm-CB-Scripts
Collection of scripts for use with Carbon Black Cb Response API
Stars: ✭ 14 (-48.15%)
Mutual labels:  edr
kirby3-instagram
Kirby 3 Plugin to call Instagram (or any other) API Endpoints
Stars: ✭ 20 (-25.93%)
Mutual labels:  endpoint
cbapi-python
Carbon Black API - Python language bindings
Stars: ✭ 140 (+418.52%)
Mutual labels:  edr
Owlyshield
Owlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact))..
Stars: ✭ 281 (+940.74%)
Mutual labels:  edr
epf-transmitter
astrizhachuk.github.io/epf-transmitter/
Stars: ✭ 32 (+18.52%)
Mutual labels:  endpoint
actix-web-grants
Authorization extension for actix-web to validate user permissions
Stars: ✭ 85 (+214.81%)
Mutual labels:  endpoint-security
TiEtwAgent
PoC memory injection detection agent based on ETW, for offensive and defensive research purposes
Stars: ✭ 135 (+400%)
Mutual labels:  edr
Speedport-Plus-Cosmote-Router-hacks
Exploring the Sercomm made router of Cosmote - OTE Group (Deutsche Telekom in Greece)
Stars: ✭ 64 (+137.04%)
Mutual labels:  endpoint
Microsoft-Defender-for-Endpoint-Queries
Microsoft Defender for Endpoint Hunting Queries
Stars: ✭ 26 (-3.7%)
Mutual labels:  edr
cassandra-data-apis
Data APIs for Apache Cassandra
Stars: ✭ 18 (-33.33%)
Mutual labels:  endpoint
pareto-mac
Automatically audit your Mac for basic security hygiene.
Stars: ✭ 223 (+725.93%)
Mutual labels:  endpoint-security
ScareCrow-CobaltStrike
Cobalt Strike script for ScareCrow payloads intergration (EDR/AV evasion)
Stars: ✭ 387 (+1333.33%)
Mutual labels:  edr
rest-api-endpoints
🌾 WordPress REST API endpoints
Stars: ✭ 31 (+14.81%)
Mutual labels:  endpoint
Splunk TA paloalto
The Palo Alto Networks Add-on for Splunk allows a Splunk® Enterprise or Splunk Cloud administrator to collect data from Palo Alto Networks Next-Generation Firewall devices and Advanced Endpoint Protection.
Stars: ✭ 15 (-44.44%)
Mutual labels:  endpoint-protection
wg-api
creates an HTTP endpoint for a Wireguard® VPN server
Stars: ✭ 61 (+125.93%)
Mutual labels:  endpoint
MediatR.AspNetCore.Endpoints
No description or website provided.
Stars: ✭ 89 (+229.63%)
Mutual labels:  endpoint
agent
This repository contains Nanny-On agent source codes. Anyone can contribute to write and update the codes. Please join us.
Stars: ✭ 14 (-48.15%)
Mutual labels:  endpoint-security
Elkeid
Elkeid is a Cloud-Native Host-Based Intrusion Detection solution project to provide next-generation Threat Detection and Behavior Audition with modern architecture.
Stars: ✭ 1,245 (+4511.11%)
Mutual labels:  edr
WhiteBeam
WhiteBeam: Transparent endpoint security
Stars: ✭ 74 (+174.07%)
Mutual labels:  edr

Awesome Endpoint Detection and Response tools

Awesome PRs Welcome License

Collection of tool you need to have in your EDR arsenal

  • The Hives Project - A scalable, open source and free Security Incident Response Platform, tightly integrated with MISP (Malware Information Sharing Platform), designed to make life easier for SOCs, CSIRTs, CERTs and any information security practitioner dealing with security incidents that need to be investigated and acted upon swiftly.
    • TheHive - A Scalable, Open Source and Free Security Incident Response Platform
    • Cortex - A Powerful Observable Analysis and Active Response Engine
    • Hippocampe - Threat Feed Aggregation, Made Easy
  • Zeek - Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
  • Mozzila Mig [Depreciated] : Distributed & real time digital forensics at the speed of the cloud.
  • Osquery - Performant endpoint visibility.
    Tool to extend Osquery :
    • AitBnB StreamAlert - StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define.
    • Fleet - A flexible control server for osquery fleets.
    • Doorman - An osquery fleet manager.
    • Palantir osquery-configuration - A repository for using osquery for incident detection and response.
    • Zentral - Zentral is an Event Hub to gather, process, and monitor system events and link them to an inventory.
    • Osquery-attck - Mapping the MITRE ATT&CK Matrix with Osquery.
    • Osquery Launcher - Osquery launcher, autoupdater, and packager.
    • osquery-python - Python bindings for osquery's Thrift API.
    • osquery-go - Go bindings for osquery.
  • Cuckoo - Cuckoo Sandbox is the leading open source automated malware analysis system (MISP)
  • Google GRR - GRR Rapid Response: remote live forensics for incident response.
  • Wazuh - The Open Source Security Platform - Wazuh helps you to gain deeper security visibility into your infrastructure by monitoring hosts at an operating system and application level. Wazuh GIT : Lot of ressources for wazuh main software.
  • MISP - MISP (core software) - Open Source Threat Intelligence and Sharing Platform (formely known as Malware Information Sharing Platform)
  • OpenEDR - By Comodo : OpenEDR allows you to analyze what’s happening across your entire environment at base-security-event level.
  • Bluespawn : An Active Defense and EDR software to empower Blue Teams.
  • OSSEC : OSSEC has a powerful correlation and analysis engine, integrating log analysis, file integrity monitoring, Windows registry monitoring, centralized policy enforcement, rootkit detection, real-time alerting and active response.
Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].