All Projects → blue-teaming-with-kql → Similar Projects or Alternatives

558 Open source projects that are alternatives of or similar to blue-teaming-with-kql

Azure-Sentinel-4-SecOps
Microsoft Sentinel SOC Operations
Stars: ✭ 140 (+37.25%)
Mutual labels:  threat-hunting, siem, azure-sentinel
Sentinel Attack
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Stars: ✭ 676 (+562.75%)
Mutual labels:  azure, threat-hunting, siem
Meerkat
A collection of PowerShell modules designed for artifact gathering and reconnaisance of Windows-based endpoints.
Stars: ✭ 284 (+178.43%)
Mutual labels:  threat-hunting, siem
Threathunting Spl
Splunk code (SPL) useful for serious threat hunters.
Stars: ✭ 117 (+14.71%)
Mutual labels:  threat-hunting, siem
Siem
SIEM Tactics, Techiques, and Procedures
Stars: ✭ 157 (+53.92%)
Mutual labels:  threat-hunting, siem
Ee Outliers
Open-source framework to detect outliers in Elasticsearch events
Stars: ✭ 172 (+68.63%)
Mutual labels:  threat-hunting, siem
SysmonConfigPusher
Pushes Sysmon Configs
Stars: ✭ 59 (-42.16%)
Mutual labels:  threat-hunting, siem
Attackdatamap
A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework
Stars: ✭ 264 (+158.82%)
Mutual labels:  threat-hunting, siem
detection-rules
Threat Detection & Anomaly Detection rules for popular open-source components
Stars: ✭ 34 (-66.67%)
Mutual labels:  threat-hunting, siem
Adaz
🔧 Automatically deploy customizable Active Directory labs in Azure
Stars: ✭ 197 (+93.14%)
Mutual labels:  azure, threat-hunting
pf-azure-sentinel
Parse pfSense/OPNSense logs using Logstash, GeoIP tag entities, add additional context to logs, then send to Azure Sentinel for analysis.
Stars: ✭ 24 (-76.47%)
Mutual labels:  kql, azure-sentinel
vuekit
Kirby 3 + Vue.js kit
Stars: ✭ 16 (-84.31%)
Mutual labels:  kql
KQL
KQL queries for Advanced Hunting
Stars: ✭ 110 (+7.84%)
Mutual labels:  kql
pyeti
Python bindings for Yeti's API
Stars: ✭ 15 (-85.29%)
Mutual labels:  threat-hunting
S2AN
S2AN - Mapper of Sigma/Suricata Rules/Signatures ➡️ MITRE ATT&CK Navigator
Stars: ✭ 70 (-31.37%)
Mutual labels:  threat-hunting
DurableDungeon
A game designed to teach and learn serverless durable functions in C#
Stars: ✭ 55 (-46.08%)
Mutual labels:  azure
AzureKusto
R interface to Kusto/Azure Data Explorer. Submit issues and PRs at https://github.com/Azure/AzureKusto
Stars: ✭ 18 (-82.35%)
Mutual labels:  azure-data-explorer
GDPatrol
A Lambda-powered Security Orchestration framework for AWS GuardDuty
Stars: ✭ 50 (-50.98%)
Mutual labels:  siem
Docker-Provider
Azure Monitor for Containers
Stars: ✭ 89 (-12.75%)
Mutual labels:  loganalytics
OSINT-Brazuca
Repositório criado com intuito de reunir informações, fontes(websites/portais) e tricks de OSINT dentro do contexto Brasil.
Stars: ✭ 508 (+398.04%)
Mutual labels:  threat-hunting
kestrel-lang
Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.
Stars: ✭ 165 (+61.76%)
Mutual labels:  threat-hunting
cli-eaa
CLI for Enterprise Application Access (EAA)
Stars: ✭ 19 (-81.37%)
Mutual labels:  siem
script-samples
A sample gallery of scripts to manage all things Microsoft 365.
Stars: ✭ 56 (-45.1%)
Mutual labels:  azure
serverless-recipes
Compendium of Serverless samples with Azure Cosmos DB
Stars: ✭ 30 (-70.59%)
Mutual labels:  azure
YAFRA
YAFRA is a semi-automated framework for analyzing and representing reports about IT Security incidents.
Stars: ✭ 22 (-78.43%)
Mutual labels:  threat-hunting
OpenSIEM-Logstash-Parsing
SIEM Logstash parsing for more than hundred technologies
Stars: ✭ 140 (+37.25%)
Mutual labels:  siem
Threat-Hunting-and-Detection
Repository for threat hunting and detection queries, tools, etc.
Stars: ✭ 261 (+155.88%)
Mutual labels:  threat-hunting
irma
enpoint detection / live analysis & sandbox host / signatures quality test
Stars: ✭ 25 (-75.49%)
Mutual labels:  threat-hunting
log2oms
A super tiny agent (binary 5MB, container 12MB) that pushs app logs to Azure Log Analytics (OMS)
Stars: ✭ 17 (-83.33%)
Mutual labels:  azure
auditbeat-in-action
Demo for Elastic's Auditbeat and SIEM
Stars: ✭ 24 (-76.47%)
Mutual labels:  siem
BLUELAY
Searches online paste sites for certain search terms which can indicate a possible data breach.
Stars: ✭ 24 (-76.47%)
Mutual labels:  threat-hunting
Memoirs-of-a-Threat-Hunter
My personal experience in Threat Hunting and knowledge gained so far.
Stars: ✭ 17 (-83.33%)
Mutual labels:  threat-hunting
Threathunting-book
Threat hunting Web Windows AD linux ATT&CK TTPs
Stars: ✭ 338 (+231.37%)
Mutual labels:  threat-hunting
support-tickets-classification
This case study shows how to create a model for text analysis and classification and deploy it as a web service in Azure cloud in order to automatically classify support tickets. This project is a proof of concept made by Microsoft (Commercial Software Engineering team) in collaboration with Endava http://endava.com/en
Stars: ✭ 142 (+39.22%)
Mutual labels:  azure
azure-kusto-java
Microsoft Azure Kusto Library for Java
Stars: ✭ 31 (-69.61%)
Mutual labels:  azure-data-explorer
sophos-central-api-connector
Leverage Sophos Central API
Stars: ✭ 17 (-83.33%)
Mutual labels:  threat-hunting
Scrummage
The Ultimate OSINT and Threat Hunting Framework
Stars: ✭ 355 (+248.04%)
Mutual labels:  threat-hunting
AnyStatus
A remote control for your CI/CD pipelines and more
Stars: ✭ 38 (-62.75%)
Mutual labels:  azure
hassh-utils
hassh-utils: Nmap NSE Script and Docker image for HASSH - the SSH client/server fingerprinting method (https://github.com/salesforce/hassh)
Stars: ✭ 41 (-59.8%)
Mutual labels:  threat-hunting
IronNetTR
Threat research and reporting from IronNet's Threat Research Teams
Stars: ✭ 36 (-64.71%)
Mutual labels:  threat-hunting
siembol
An open-source, real-time Security Information & Event Management tool based on big data technologies, providing a scalable, advanced security analytics framework.
Stars: ✭ 153 (+50%)
Mutual labels:  siem
aks-azuredevops-agent
Self-hosted Azure DevOps Agent on Azure Kubernetes
Stars: ✭ 29 (-71.57%)
Mutual labels:  azure
sqhunter
A simple threat hunting tool based on osquery, Salt Open and Cymon API
Stars: ✭ 64 (-37.25%)
Mutual labels:  threat-hunting
fastfinder
Incident Response - Fast suspicious file finder
Stars: ✭ 116 (+13.73%)
Mutual labels:  threat-hunting
azure
VM-Series ARM Templates for Microsoft Azure
Stars: ✭ 87 (-14.71%)
Mutual labels:  azure
YaraHunts
Random hunting ordiented yara rules
Stars: ✭ 86 (-15.69%)
Mutual labels:  threat-hunting
Kong-API-Manager
Kong API Manager with Prometheus And Graylog
Stars: ✭ 78 (-23.53%)
Mutual labels:  siem
azure-kusto-node
NodeJS SDK for the Kusto service
Stars: ✭ 40 (-60.78%)
Mutual labels:  azure-data-explorer
ir scripts
incident response scripts
Stars: ✭ 17 (-83.33%)
Mutual labels:  threat-hunting
ETWNetMonv3
ETWNetMonv3 is simple C# code for Monitoring TCP Network Connection via ETW & ETWProcessMon/2 is for Monitoring Process/Thread/Memory/Imageloads/TCPIP via ETW + Detection for Remote-Thread-Injection & Payload Detection by VirtualMemAlloc Events (in-memory) etc.
Stars: ✭ 32 (-68.63%)
Mutual labels:  threat-hunting
PowerGRR
PowerGRR is an API client library in PowerShell working on Windows, Linux and macOS for GRR automation and scripting.
Stars: ✭ 52 (-49.02%)
Mutual labels:  threat-hunting
ServerlessDeviceOfflineDetection
How to detect device status with Azure Durable Entities
Stars: ✭ 21 (-79.41%)
Mutual labels:  azure
opal
Policy and data administration, distribution, and real-time updates on top of Open Policy Agent
Stars: ✭ 459 (+350%)
Mutual labels:  azure
Logmira
Logmira by Blumira has been created by Amanda Berlin as a helpful download of Microsoft Windows Domain Group Policy Object settings.
Stars: ✭ 46 (-54.9%)
Mutual labels:  siem
MindMaps
#ThreatHunting #DFIR #Malware #Detection Mind Maps
Stars: ✭ 224 (+119.61%)
Mutual labels:  threat-hunting
siemstress
Very basic CLI SIEM (Security Information and Event Management system).
Stars: ✭ 24 (-76.47%)
Mutual labels:  siem
kafka-sink-azure-kusto
Kafka sink for Kusto
Stars: ✭ 33 (-67.65%)
Mutual labels:  azure-data-explorer
censys-recon-ng
recon-ng modules for Censys
Stars: ✭ 29 (-71.57%)
Mutual labels:  threat-hunting
ansible-splunk-playbook
Install a full Splunk Enterprise Cluster or Universal forwarder using an ansible playbook
Stars: ✭ 34 (-66.67%)
Mutual labels:  siem
skalogs-bundle
Open Source data and event driven real time Monitoring and Analytics Platform
Stars: ✭ 16 (-84.31%)
Mutual labels:  siem
1-60 of 558 similar projects