Awesome Detection Engineering
Section: Detection Content & Signatures · Sigma's repository of turnkey detection content. Content can be converted for use with most SIEMs.
Entry
Appears in 5 awesome lists
Sigma's repository of turnkey detection content. Content can be converted for use with most SIEMs.
Section: Detection Content & Signatures · Sigma's repository of turnkey detection content. Content can be converted for use with most SIEMs.
Section: Log Analysis Tools · Generic signature format for SIEM systems already containing an extensive ruleset.
Section: THREAT INTEL · Generic signature format for SIEM systems.
Section: Detection Rules · Generic Signature Format for SIEM Systems
Section: Other · Main Sigma Rule Repository
A partially free website research tool. Collects detailed information about IP, whois, ssl, dns, ports, threats reports, geolocation, cookies, metadata (fb app id etc). Make screenshots and many others
A Free cybercrime intelligence toolset that can indicate if a specific APK package was compromised in an Infostealer malware attack.
AbuseIPDB is a project dedicated to helping combat the spread of hackers, spammers, and abusive activity on the internet.
MISP threat sharing platform is a free and open source software helping information sharing of threat intelligence including cyber security indicators. A threat intelligence platform for gathering, sharing, storing and correlating Indicators of Compromise of targeted attacks, threat intelligence,…
Tool to investigate malicious Windows logon by visualizing and analyzing Windows event log.
The foundational framework of adversary tactics, techniques, and procedures based on real-world observations.
The threat intelligence organization at the center of the Cisco Security portfolio
An Open Source Intelligence, or OSINT solution to get threat intelligence data about a specific file, an IP or a domain from a single API at scale.