BernaldoPenasAntelo's Stars
corelight/phantom-playbooks
corelight/zeek-openvpn
A Zeek OpenVPN protocol analyzer plugin.
ComodoSecurity/openedr
Open EDR public repository
HKcyberstark/wazuh-ecs
Parse wazuh[HIDS] alerts into ECS mapping using Filebeat
bammv/sguil
Sguil client for NSM
limbenjamin/nTimetools
Timestomper and Timestamp checker with nanosecond accuracy for NTFS volumes
MicrosoftDocs/sysinternals
Content for sysinternals.com
SECFORCE/Tunna
Tunna is a set of tools which will wrap and tunnel any TCP communication over HTTP. It can be used to bypass network restrictions in fully firewalled environments.
grapheneX/grapheneX
Automated System Hardening Framework
floe/tuxblet
robcowart/synesis_lite_suricata
Suricata IDS/IPS log analytics using the Elastic Stack.
OTRF/OSSEM
Open Source Security Events Metadata (OSSEM)
defenxor/dsiem
Security event correlation engine for ELK stack
endgameinc/eqllib
imamimam/EVTX-ATTACK-SAMPLES-
redcanaryco/atomic-red-team
Small and highly portable detection tests based on MITRE's ATT&CK.
ThreatHuntingProject/ThreatHunting
An informational repo about hunting for adversaries in your IT environment.
olafhartong/sysmon-modular
A repository of sysmon configuration modules
Kirtar22/Litmus_Test
Detecting ATT&CK techniques & tactics for Linux
sametsazak/sysmon
Sysmon and wazuh integration with Sigma sysmon rules [updated]
Yara-Rules/rules
Repository of yara rules
sbousseaden/EVTX-ATTACK-SAMPLES
Windows Events Attack Samples