All Projects → eshlomo1 → Azure-Sentinel-4-SecOps

eshlomo1 / Azure-Sentinel-4-SecOps

Licence: MIT license
Microsoft Sentinel SOC Operations

Programming Languages

powershell
5483 projects
HTML
75241 projects
CSS
56736 projects
M4
1887 projects

Projects that are alternatives of or similar to Azure-Sentinel-4-SecOps

Patrowlengines
PatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform
Stars: ✭ 162 (+15.71%)
Mutual labels:  incident-response, threat-hunting, threat-intelligence
Intelowl
Intel Owl: analyze files, domains, IPs in multiple ways from a single API at scale
Stars: ✭ 2,114 (+1410%)
Mutual labels:  incident-response, threat-hunting, threat-intelligence
blue-teaming-with-kql
Repository with Sample KQL Query examples for Threat Hunting
Stars: ✭ 102 (-27.14%)
Mutual labels:  threat-hunting, siem, azure-sentinel
GDPatrol
A Lambda-powered Security Orchestration framework for AWS GuardDuty
Stars: ✭ 50 (-64.29%)
Mutual labels:  incident-response, siem, cloudsecurity
Patrowlmanager
PatrOwl - Open Source, Smart and Scalable Security Operations Orchestration Platform
Stars: ✭ 363 (+159.29%)
Mutual labels:  incident-response, threat-hunting, threat-intelligence
Patrowldocs
PatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform
Stars: ✭ 105 (-25%)
Mutual labels:  incident-response, threat-hunting, threat-intelligence
MindMaps
#ThreatHunting #DFIR #Malware #Detection Mind Maps
Stars: ✭ 224 (+60%)
Mutual labels:  incident-response, threat-hunting, threat-intelligence
YAFRA
YAFRA is a semi-automated framework for analyzing and representing reports about IT Security incidents.
Stars: ✭ 22 (-84.29%)
Mutual labels:  incident-response, threat-hunting, threat-intelligence
Watcher
Watcher - Open Source Cybersecurity Threat Hunting Platform. Developed with Django & React JS.
Stars: ✭ 324 (+131.43%)
Mutual labels:  incident-response, threat-hunting, threat-intelligence
Ioc Explorer
Explore Indicators of Compromise Automatically
Stars: ✭ 73 (-47.86%)
Mutual labels:  incident-response, threat-hunting, threat-intelligence
Mthc
All-in-one bundle of MISP, TheHive and Cortex
Stars: ✭ 134 (-4.29%)
Mutual labels:  incident-response, threat-hunting, threat-intelligence
Weffles
Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI
Stars: ✭ 176 (+25.71%)
Mutual labels:  incident-response, threat-hunting
Scot
Sandia Cyber Omni Tracker (SCOT)
Stars: ✭ 206 (+47.14%)
Mutual labels:  incident-response, threat-intelligence
Oriana
Oriana is a threat hunting tool that leverages a subset of Windows events to build relationships, calculate totals and run analytics. The results are presented in a Web layer to help defenders identify outliers and suspicious behavior on corporate environments.
Stars: ✭ 152 (+8.57%)
Mutual labels:  incident-response, threat-hunting
malware-persistence
Collection of malware persistence and hunting information. Be a persistent persistence hunter!
Stars: ✭ 109 (-22.14%)
Mutual labels:  threat-hunting, threat-intelligence
Vast
🔮 Visibility Across Space and Time
Stars: ✭ 227 (+62.14%)
Mutual labels:  incident-response, siem
evtx-hunter
evtx-hunter helps to quickly spot interesting security-related activity in Windows Event Viewer (EVTX) files.
Stars: ✭ 122 (-12.86%)
Mutual labels:  incident-response, threat-hunting
mail to misp
Connect your mail client/infrastructure to MISP in order to create events based on the information contained within mails.
Stars: ✭ 61 (-56.43%)
Mutual labels:  threat-hunting, threat-intelligence
LogESP
Open Source SIEM (Security Information and Event Management system).
Stars: ✭ 162 (+15.71%)
Mutual labels:  secops, siem
CCXDigger
The CyberCX Digger project is designed to help Australian organisations determine if they have been impacted by certain high profile cyber security incidents. Digger provides threat hunting functionality packaged in a simple-to-use tool, allowing users to detect certain attacker activities; all for free.
Stars: ✭ 45 (-67.86%)
Mutual labels:  incident-response, threat-intelligence

Microsoft Sentinel - SEC Operations

Welcome to the Microsoft Sentinel - SOC Operations

This repository contains many Microsoft Sentinel content with queries for exploration, hunting, and other activities.

Resources

Azure Sentinel Posts on Elli Shlomo blog

Contributing

This project welcomes contributions and suggestions. Most contributions require you to agree to a Contributor License Agreement (CLA) declaring that you have the right to and actually do, grant us the rights to use your contribution.

Note that the project description data, including the texts, logos, images, and/or trademarks, for each open source project belongs to its rightful owner. If you wish to add or remove any projects, please contact us at [email protected].