Found 16,575 repositories(showing 30)
wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
SigmaHQ
Main Sigma Rule Repository
Graylog2
Free and open log management
Azure
Cloud-native SIEM for intelligent security analytics for your entire enterprise.
pawelgrzybek
Siema - Lightweight and simple carousel in pure JavaScript
outflanknl
Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.
mikeroyal
Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.
mozilla
DEPRECATED - MozDef: Mozilla Enterprise Defense Platform
sherifabdlnaby
๐ณ Elastic Stack (ELK) v9+ on Docker with Compose. Pre-configured out of the box to enable Logging, Metrics, APM, Alerting, ML, and SIEM features. Up with a Single Command.
VictoriaMetrics
Fast and easy to use database for logs, which can efficiently handle terabytes of logs
cyb3rxp
A curated knowledge base to build, run and mature a SOC (including CSIRT).
matanolabs
Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS
mthcht
Awesome Security lists for SOC/CERT/CTI
tirrenotechnologies
tirreno is an open-source security framework. Event tracking, threat detection, and risk scoring for any application.
pfelk
pfSense/OPNsense + Elastic Stack
edoardogerosa
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
mikeroyal
Open Source Security Guide. Learn all about Security Standards (FIPS, CIS, FedRAMP, FISMA, etc.), Frameworks, Threat Models, Encryption, and Benchmarks.
jaegeral
A collective list of public APIs for use in security. Contributions welcome
nsacyber
Configuration guidance for implementing collection of security relevant Windows Event Log events by using Windows Event Forwarding. #nsacyber
threathunters-io
Transform Linux Audit logs for SIEM usage
FalconForceTeam
FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log aggregation tool.
tenzir
Tenzir is the data pipeline engine for security teams.
FunnyWolf
Agentic SOC Platform: A powerful, flexible, open-source, and agent-centric automated security operations platform
TonyPhipps
SIEM Tactics, Techiques, and Procedures
runreveal
Pipelined Query Language
aws-samples
A solution for collecting, correlating and visualizing multiple types of logs to help investigate security incidents.
mthcht
Awesome list of keywords and artifacts for Threat Hunting sessions
iknowjason
A little tool to play with Azure Identity - Azure and Entra ID lab creation tool. Blog: https://medium.com/@iknowjason/sentinel-for-purple-teaming-183b7df7a2f4
mdecrevoisier
Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.
utmstack
Enterprise-ready SIEM, SOAR and Compliance powered by real-time correlation and threat intelligence.