All Projects → Whids → Similar Projects or Alternatives

285 Open source projects that are alternatives of or similar to Whids

Threathunter Playbook
A Threat hunter's playbook to aid the development of techniques and hypothesis for hunting campaigns.
Stars: ✭ 2,879 (+1431.38%)
Mutual labels:  dfir, threat-hunting, sysmon
TA-Sysmon-deploy
Deploy and maintain Symon through the Splunk Deployment Sever
Stars: ✭ 31 (-83.51%)
Mutual labels:  dfir, sysmon, threat-hunting
ir scripts
incident response scripts
Stars: ✭ 17 (-90.96%)
Mutual labels:  dfir, sysmon, threat-hunting
Sysmon Modular
A repository of sysmon configuration modules
Stars: ✭ 1,229 (+553.72%)
Mutual labels:  dfir, threat-hunting, sysmon
Threathunt
ThreatHunt is a PowerShell repository that allows you to train your threat hunting skills.
Stars: ✭ 92 (-51.06%)
Mutual labels:  dfir, threat-hunting
SysmonResources
Consolidation of various resources related to Microsoft Sysmon & sample data/log
Stars: ✭ 64 (-65.96%)
Mutual labels:  sysmon, threat-hunting
Oriana
Oriana is a threat hunting tool that leverages a subset of Windows events to build relationships, calculate totals and run analytics. The results are presented in a Web layer to help defenders identify outliers and suspicious behavior on corporate environments.
Stars: ✭ 152 (-19.15%)
Mutual labels:  dfir, threat-hunting
Detectionlab
Automate the creation of a lab environment complete with security tooling and logging best practices
Stars: ✭ 3,237 (+1621.81%)
Mutual labels:  dfir, sysmon
Security Onion
Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
Stars: ✭ 2,956 (+1472.34%)
Mutual labels:  ids, dfir
Slides
Misc Threat Hunting Resources
Stars: ✭ 203 (+7.98%)
Mutual labels:  dfir, threat-hunting
Malwless
Test Blue Team detections without running any attack.
Stars: ✭ 215 (+14.36%)
Mutual labels:  dfir, sysmon
MindMaps
#ThreatHunting #DFIR #Malware #Detection Mind Maps
Stars: ✭ 224 (+19.15%)
Mutual labels:  dfir, threat-hunting
Teler
Real-time HTTP Intrusion Detection
Stars: ✭ 1,248 (+563.83%)
Mutual labels:  ids, threat-hunting
Detectionlabelk
DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.
Stars: ✭ 273 (+45.21%)
Mutual labels:  dfir, threat-hunting
Threatpinchlookup
Documentation and Sharing Repository for ThreatPinch Lookup Chrome & Firefox Extension
Stars: ✭ 257 (+36.7%)
Mutual labels:  dfir, threat-hunting
Mthc
All-in-one bundle of MISP, TheHive and Cortex
Stars: ✭ 134 (-28.72%)
Mutual labels:  dfir, threat-hunting
rhq
Recon Hunt Queries
Stars: ✭ 66 (-64.89%)
Mutual labels:  dfir, threat-hunting
Signature Base
Signature base for my scanner tools
Stars: ✭ 1,212 (+544.68%)
Mutual labels:  dfir, threat-hunting
Sysmon Config
Sysmon configuration file template with default high-quality event tracing
Stars: ✭ 3,287 (+1648.4%)
Mutual labels:  threat-hunting, sysmon
Sentinel Attack
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Stars: ✭ 676 (+259.57%)
Mutual labels:  threat-hunting, sysmon
Threatbus
🚌 The missing link to connect open-source threat intelligence tools.
Stars: ✭ 139 (-26.06%)
Mutual labels:  ids, threat-hunting
SysmonConfigPusher
Pushes Sysmon Configs
Stars: ✭ 59 (-68.62%)
Mutual labels:  sysmon, threat-hunting
Evtx Attack Samples
Windows Events Attack Samples
Stars: ✭ 1,243 (+561.17%)
Mutual labels:  dfir, threat-hunting
fastfinder
Incident Response - Fast suspicious file finder
Stars: ✭ 116 (-38.3%)
Mutual labels:  dfir, threat-hunting
Sigma
Generic Signature Format for SIEM Systems
Stars: ✭ 4,418 (+2250%)
Mutual labels:  ids, sysmon
Threatingestor
Extract and aggregate threat intelligence.
Stars: ✭ 439 (+133.51%)
Mutual labels:  dfir, threat-hunting
Threathunting
A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
Stars: ✭ 738 (+292.55%)
Mutual labels:  dfir, threat-hunting
Beagle
Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
Stars: ✭ 976 (+419.15%)
Mutual labels:  dfir, threat-hunting
Attackdatamap
A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework
Stars: ✭ 264 (+40.43%)
Mutual labels:  dfir, threat-hunting
Sysmontools
Utilities for Sysmon
Stars: ✭ 903 (+380.32%)
Mutual labels:  threat-hunting, sysmon
Yeti
Your Everyday Threat Intelligence
Stars: ✭ 1,037 (+451.6%)
Mutual labels:  dfir, threat-hunting
Cirtkit
Tools for the Computer Incident Response Team 💻
Stars: ✭ 117 (-37.77%)
Mutual labels:  dfir
Siem
SIEM Tactics, Techiques, and Procedures
Stars: ✭ 157 (-16.49%)
Mutual labels:  threat-hunting
Threathunting Spl
Splunk code (SPL) useful for serious threat hunters.
Stars: ✭ 117 (-37.77%)
Mutual labels:  threat-hunting
Cacador
Indicator Extractor
Stars: ✭ 115 (-38.83%)
Mutual labels:  dfir
Imago Forensics
Imago is a python tool that extract digital evidences from images.
Stars: ✭ 175 (-6.91%)
Mutual labels:  dfir
Threathunting
Tools for hunting for threats.
Stars: ✭ 153 (-18.62%)
Mutual labels:  threat-hunting
Macos Attack Dataset
JSON DataSet for macOS mapped to MITRE ATT&CK Tactics.
Stars: ✭ 116 (-38.3%)
Mutual labels:  threat-hunting
Awesome Threat Detection
A curated list of awesome threat detection and hunting resources
Stars: ✭ 1,804 (+859.57%)
Mutual labels:  threat-hunting
Bearded Avenger
CIF v3 -- the fastest way to consume threat intelligence
Stars: ✭ 152 (-19.15%)
Mutual labels:  threat-hunting
Invoke Liveresponse
Invoke-LiveResponse
Stars: ✭ 115 (-38.83%)
Mutual labels:  dfir
Misp Warninglists
Warning lists to inform users of MISP about potential false-positives or other information in indicators
Stars: ✭ 184 (-2.13%)
Mutual labels:  dfir
Ee Outliers
Open-source framework to detect outliers in Elasticsearch events
Stars: ✭ 172 (-8.51%)
Mutual labels:  threat-hunting
Lolbas
Living Off The Land Binaries And Scripts - (LOLBins and LOLScripts)
Stars: ✭ 1,506 (+701.06%)
Mutual labels:  dfir
Analyst Arsenal
A toolkit for Security Researchers
Stars: ✭ 112 (-40.43%)
Mutual labels:  threat-hunting
Kiewtai
A port of Kaitai to the Hiew hex editor
Stars: ✭ 108 (-42.55%)
Mutual labels:  dfir
Opensquat
Detection of phishing domains and domain squatting. Supports permutations such as homograph attack, typosquatting and bitsquatting.
Stars: ✭ 149 (-20.74%)
Mutual labels:  threat-hunting
Patrowldocs
PatrOwl - Open Source, Free and Scalable Security Operations Orchestration Platform
Stars: ✭ 105 (-44.15%)
Mutual labels:  threat-hunting
Awesome Forensics
A curated list of awesome forensic analysis tools and resources
Stars: ✭ 1,775 (+844.15%)
Mutual labels:  dfir
Zombieant
Zombie Ant Farm: Primitives and Offensive Tooling for Linux EDR evasion.
Stars: ✭ 169 (-10.11%)
Mutual labels:  dfir
Intelowl
Intel Owl: analyze files, domains, IPs in multiple ways from a single API at scale
Stars: ✭ 2,114 (+1024.47%)
Mutual labels:  threat-hunting
Awesome Yara
A curated list of awesome YARA rules, tools, and people.
Stars: ✭ 1,394 (+641.49%)
Mutual labels:  threat-hunting
Dovehawk
Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings
Stars: ✭ 97 (-48.4%)
Mutual labels:  threat-hunting
Thehive4py
Python API Client for TheHive
Stars: ✭ 143 (-23.94%)
Mutual labels:  dfir
Detections
This repository contains all public indicators identified by 401trg during the course of our investigations. It also includes relevant yara rules and ids signatures to detect these indicators.
Stars: ✭ 95 (-49.47%)
Mutual labels:  threat-hunting
Attack monitor
Endpoint detection & Malware analysis software
Stars: ✭ 186 (-1.06%)
Mutual labels:  sysmon
Weffles
Build a fast, free, and effective Threat Hunting/Incident Response Console with Windows Event Forwarding and PowerBI
Stars: ✭ 176 (-6.38%)
Mutual labels:  threat-hunting
Shhmon
Neutering Sysmon via driver unload
Stars: ✭ 166 (-11.7%)
Mutual labels:  sysmon
Suricata Update
The tool for updating your Suricata rules.
Stars: ✭ 143 (-23.94%)
Mutual labels:  ids
Patrowlhears
PatrowlHears - Vulnerability Intelligence Center / Exploits
Stars: ✭ 89 (-52.66%)
Mutual labels:  threat-hunting
1-60 of 285 similar projects