Skip to content

Entry

Sigma

Appears in 5 awesome lists

Sigma's repository of turnkey detection content. Content can be converted for use with most SIEMs.

Open github.comsigmahq/sigma

Found in these lists

Awesome Detection Engineering

Section: Detection Content & Signatures · Sigma's repository of turnkey detection content. Content can be converted for use with most SIEMs.

FreshScore 78

Awesome Incident Response

Section: Log Analysis Tools · Generic signature format for SIEM systems already containing an extensive ruleset.

ActiveScore 82

SOCIAL MEDIA

Section: THREAT INTEL · Generic signature format for SIEM systems.

FreshScore 86

awesome-python

Section: Other · Main Sigma Rule Repository

FreshScore 81

Awesome Threat Detection and Hunting

Section: Detection Rules · Generic Signature Format for SIEM Systems

SlowScore 61

Pulsedive

A partially free website research tool. Collects detailed information about IP, whois, ssl, dns, ports, threats reports, geolocation, cookies, metadata (fb app id etc). Make screenshots and many others

In 7 listsDetails

Hudson Rock

A Free cybercrime intelligence toolset that can indicate if a specific APK package was compromised in an Infostealer malware attack.

In 6 listsDetails

AbuseIPDB

AbuseIPDB is a project dedicated to helping combat the spread of hackers, spammers, and abusive activity on the internet.

In 5 listsDetails

Malware Information Sharing Platform and Threat Sharing (MISP)

MISP threat sharing platform is a free and open source software helping information sharing of threat intelligence including cyber security indicators. A threat intelligence platform for gathering, sharing, storing and correlating Indicators of Compromise of targeted attacks, threat intelligence,…

In 5 listsDetails

LogonTracer

Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.

In 5 listsDetails

MITRE ATT&CK

The foundational framework of adversary tactics, techniques, and procedures based on real-world observations.

In 4 listsDetails

Cisco Talos

The threat intelligence organization at the center of the Cisco Security portfolio

In 4 listsDetails

intelowlproject/IntelOwl

An Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale.

In 4 listsDetails