Back to rankings

edoardogerosa/sentinel-attack

Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK

siemthreat-huntingazure-sentinelmitre-attacksysmonsysmon-configazureblue-teamcybersecurityloggingsecurity-toolsdetection
Star Growth
Stars
1.1k
Forks
200
Weekly Growth
Issues
10
1.1k
Jul 18Jul 19Jul 20Jul 20
README

GitHub release Maintenance PRs Welcome

Sentinel ATT&CK aims to simplify the rapid deployment of a threat hunting capability that leverages Sysmon and MITRE ATT&CK on Azure Sentinel.

It provides a Sysmon log parser mapped against the OSSEM data model and compatible with the Sysmon Modular XML configuration file.

DISCLAIMER: This tool requires tuning and investigative trialling to be truly effective in a production environment.

Usage

To use the Sentinel-ATT&CK parser, copy-paste it into your Sentinel Logs blade and store it as a function named Sysmon.

A copy of the DEF CON 27 cloud village presentation introducing Sentinel ATT&CK can be found here and here.

Contributing

This repository is work in progress, if you spot any problems we welcome pull requests or submissions on the issue tracker.

Authors and contributors

Sentinel ATT&CK is built with ❤ by:

  • Edoardo Gerosa Twitter Follow

Special thanks go to the following contributors:

Related repositories
wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

C++Othersecuritycompliance
wazuh.com
16.2k2.4k
SigmaHQ/sigma

Main Sigma Rule Repository

PythonPyPIOthersecuritymonitoring
sigmahq.io
10.8k2.7k
Graylog2/graylog2-server

Free and open log management

JavaMavenOtherlog-analysislog-collector
graylog.org
8.1k1.1k
mikeroyal/Digital-Forensics-Guide

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

PythonPyPIdigitalforensicsdigitalforensicreadiness
3k356
outflanknl/RedELK

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

PythonPyPIBSD 3-Clause "New" or "Revised" Licensesecuritysiem
2.7k394
mozilla/MozDef

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

PythonPyPIMozilla Public License 2.0siempython
2.2k323
sherifabdlnaby/elastdocker

🐳 Elastic Stack (ELK) v9+ on Docker with Compose. Pre-configured out of the box to enable Logging, Metrics, APM, Alerting, ML, and SIEM features. Up with a Single Command.

DockerfileMIT Licenseelkelk-stack
towardsdatascience.com/running-securing-and-deploying-elastic-stack-on-docker-f1a8ebf1dc5b
2.1k339
VictoriaMetrics/VictoriaLogs

Fast and easy to use database for logs, which can efficiently handle terabytes of logs

GoGo ModulesApache License 2.0elasticsearchlogs
docs.victoriametrics.com/victorialogs/
2.1k159
cyb3rxp/awesome-soc

A curated knowledge base to build, run and mature a SOC (including CSIRT).

Creative Commons Zero v1.0 Universalcertcsirt
1.8k280
mthcht/awesome-lists

Awesome Security lists for SOC/CERT/CTI

YARAMIT Licenseblueteamhacktools
1.8k212
matanolabs/matano

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Rustcrates.ioApache License 2.0awscloud
matano.dev
1.7k122
beenuar/AiSOC

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.

PythonPyPIMIT Licenseai-securityalert-triage
tryaisoc.com
1.5k169