Marsidi's Stars
socfortress/Playbooks
Playbooks for SOC Analysts
socfortress/Wazuh-Rules
Advanced Wazuh Rules for more accurate threat detection. Feel free to implement within your own Wazuh environment, contribute, or fork!
palantir/windows-event-forwarding
A repository for using windows event forwarding for incident detection and response
V1D1AN/S1EM
This project is a SIEM with SIRP and Threat Intel, all in one.
swimlane/elk-tls-docker
This repository contains code to create a ELK stack with certificates & security enabled using docker-compose
BlackPerl-DFIR/SOC-OpenSource
This is a Project Designed for Security Analysts and all SOC audiences who wants to play with implementation and explore the Modern SOC architecture.
3CORESec/SIEGMA
SIEGMA - Transform Sigma rules into SIEM consumables
JPCERTCC/LogonTracer
Investigate malicious Windows logon by visualizing and analyzing Windows event log
nasbench/SIGMA-Resources
Resources To Learn And Understand SIGMA Rules
elastic/detection-rules
stuhli/awesome-event-ids
Collection of Event ID ressources useful for Digital Forensics and Incident Response
microsoft/Microsoft-365-Defender-Hunting-Queries
Sample queries for Advanced hunting in Microsoft 365 Defender
picussecurity/picuslabs
Picus Labs
vinyll/django-imagefit
Resize an image on render. Preserve your original file on your system.
sbousseaden/EVTX-ATTACK-SAMPLES
Windows Events Attack Samples
Cyb3rWard0g/Invoke-ATTACKAPI
A PowerShell script to interact with the MITRE ATT&CK Framework via its own API
mitre/cti
Cyber Threat Intelligence Repository expressed in STIX 2.0
mitre-attack/tram
Threat Report ATT&CK™ Mapping (TRAM) is a tool to aid analyst in mapping finished reports to ATT&CK.
atc-project/atomic-threat-coverage
Actionable analytics designed to combat threats
xenoscr/atomiccaldera
A MITRE Caldera plugin written in Python 3 used to convert Red Canary Atomic Red Team Tests to MITRE Caldera Stockpile YAML ability files.
OTRF/ATTACK-Python-Client
Python Script to access ATT&CK content available in STIX via a public TAXII server
guardicore/monkey
Infection Monkey - An open-source adversary emulation platform
NextronSystems/APTSimulator
A toolset to make a system look as if it was the victim of an APT attack
uber-common/metta
An information security preparedness tool to do adversarial simulation.
endgameinc/RTA
jymcheong/AutoTTP
Automated Tactics Techniques & Procedures
praetorian-inc/purple-team-attack-automation
Praetorian's public release of our Metasploit automation of MITRE ATT&CK™ TTPs
SigmaHQ/sigma
Main Sigma Rule Repository
mitre/cascade-server
CASCADE Server
mitre/caldera
Automated Adversary Emulation Platform