amirzargaran
SOC the Next-Gen Architect & Open-Source SIEM and related tools implementor and deployer
SOC 724
Pinned Repositories
alerting
📟 Get notified when your data meets certain conditions by setting up monitors, alerts, and notifications
AlertLogic_Waf4CEF
This is customized ArcSight Syslog Flex Connector file for normalizing the Web Application Firewall of Alert Logic Events and converting to CEF (Common Event Format) format.
arcsight-parsers
ArcSight parsers
ArcSight-TheHive-Alert
And now, for the first time, you can send alerts via action from ArcSight ESM Console to the TheHive when Correlation Rules are triggered.
ArcSight-Zulip-Alert
In the ArcSight ESM, you can send the results of matched correlation rules as an ExecuteCommand type. One of the best messaging platforms is Zulip. This repository helps you to integrate ArcSight ESM and Zulip by ExecuteCommand alert action.
ArcSight_vs_Zabbix
this code is a .properties parser flex Connector file that can parse all zabbix activities to ArcSight Destination from SmartConnectors
CEFforWallix
This repository is a parser file for converting raw syslog events of Wallix PAM system to CEF(Common Event Format) format.
nginx_vs_ArcSight
Flex Connector Parser for Nginx Web Server
Sophos_Mail_Gateway_for_ArcSight_CEF
This is a Flex File Connector Parser for Sophos UTM Email Gateway
Sophos_UTM_for_CEF
This is a parser upon CEF syslog ArcSight Flex Connector for Sophos UTM devices. you can use this *.properties file in ArcSight Smart Connector as syslog listener connector for normalization and converting the raw syslog events sent from Sophos appliance to CEF format.
amirzargaran's Repositories
amirzargaran/ArcSight-TheHive-Alert
And now, for the first time, you can send alerts via action from ArcSight ESM Console to the TheHive when Correlation Rules are triggered.
amirzargaran/ArcSight_vs_Zabbix
this code is a .properties parser flex Connector file that can parse all zabbix activities to ArcSight Destination from SmartConnectors
amirzargaran/CEFforWallix
This repository is a parser file for converting raw syslog events of Wallix PAM system to CEF(Common Event Format) format.
amirzargaran/nginx_vs_ArcSight
Flex Connector Parser for Nginx Web Server
amirzargaran/alerting
📟 Get notified when your data meets certain conditions by setting up monitors, alerts, and notifications
amirzargaran/AlertLogic_Waf4CEF
This is customized ArcSight Syslog Flex Connector file for normalizing the Web Application Firewall of Alert Logic Events and converting to CEF (Common Event Format) format.
amirzargaran/arcsight-parsers
ArcSight parsers
amirzargaran/ArcSight-Zulip-Alert
In the ArcSight ESM, you can send the results of matched correlation rules as an ExecuteCommand type. One of the best messaging platforms is Zulip. This repository helps you to integrate ArcSight ESM and Zulip by ExecuteCommand alert action.
amirzargaran/Sophos_Mail_Gateway_for_ArcSight_CEF
This is a Flex File Connector Parser for Sophos UTM Email Gateway
amirzargaran/Sophos_UTM_for_CEF
This is a parser upon CEF syslog ArcSight Flex Connector for Sophos UTM devices. you can use this *.properties file in ArcSight Smart Connector as syslog listener connector for normalization and converting the raw syslog events sent from Sophos appliance to CEF format.
amirzargaran/ArcSight_Vs_PaloAlto
This is A parser file in ArcSight Integration Flex Connector for PaloAlto Devices.
amirzargaran/ArcSight_Vs_Solarwinds
this code is a .properties file that can parse all db activities of Solarwinds Mssql Server to ArcSight Destination from SmartConnectors
amirzargaran/Cortex
Cortex: a Powerful Observable Analysis and Active Response Engine
amirzargaran/elastalert2
ElastAlert 2 is a continuation of the original yelp/elastalert project. Pull requests are appreciated!
amirzargaran/IBMBigfix_Vs_ArcSight
amirzargaran/Ldap2CEF
This Parser is ArcSight Flex File Connector for OpenLdap V3 Sevice Logs
amirzargaran/MISP
MISP (core software) - Open Source Threat Intelligence and Sharing Platform
amirzargaran/OpenSearch
🔎 Open source distributed and RESTful search engine.
amirzargaran/opensearch-build
🧰 OpenSearch / OpenSearch-Dashboards Build Systems
amirzargaran/OSSEC_Vs_ArcSight
this code is a .properties file that can parse all db activities of ossec mysql db to ArcSight Destination from SmartConnectors
amirzargaran/Splunkenizer
Ansible framework providing a fast and simple way to spin up complex Splunk environments.
amirzargaran/TA-thehive-cortex
Technical add-on for Splunk related to TheHive/Cortex from TheHive project
amirzargaran/TheHive
TheHive: a Scalable, Open Source and Free Security Incident Response Platform
amirzargaran/ThreatHunting
A Splunk app mapped to MITRE ATT&CK to guide your threat hunts
amirzargaran/ThreatIngestor
Extract and aggregate threat intelligence.