edoardogerosa/sentinel-attack

Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK

siemthreat-huntingazure-sentinelmitre-attacksysmonsysmon-configazureblue-teamcybersecurityloggingsecurity-toolsdetection
Star 增长趋势
Star
1.1k
Forks
201
周增长
+0
Issues
10
1.1k1.1k1.1k1.1k1.1k
25年11月26年2月26年5月26年9月
README

GitHub release Maintenance PRs Welcome

Sentinel ATT&CK aims to simplify the rapid deployment of a threat hunting capability that leverages Sysmon and MITRE ATT&CK on Azure Sentinel.

It provides a Sysmon log parser mapped against the OSSEM data model and compatible with the Sysmon Modular XML configuration file.

DISCLAIMER: This tool requires tuning and investigative trialling to be truly effective in a production environment.

Usage

To use the Sentinel-ATT&CK parser, copy-paste it into your Sentinel Logs blade and store it as a function named Sysmon.

A copy of the DEF CON 27 cloud village presentation introducing Sentinel ATT&CK can be found here and here.

Contributing

This repository is work in progress, if you spot any problems we welcome pull requests or submissions on the issue tracker.

Authors and contributors

Sentinel ATT&CK is built with ❤ by:

  • Edoardo Gerosa Twitter Follow

Special thanks go to the following contributors:

相关仓库
wazuh/wazuh

Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

C++Othersecuritycompliance
wazuh.com
16.8k2.5k
SigmaHQ/sigma

Main Sigma Rule Repository

PythonPyPIOthersecuritymonitoring
sigmahq.io
11k2.8k
Graylog2/graylog2-server

Free and open log management

JavaMavenOtherlog-analysislog-collector
graylog.org
8.1k1.1k
mikeroyal/Digital-Forensics-Guide

Digital Forensics Guide. Learn all about Digital Forensics, Computer Forensics, Mobile device Forensics, Network Forensics, and Database Forensics.

PythonPyPItutorialdigitalforensicsdigitalforensicreadiness
3.1k394
outflanknl/RedELK

Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

PythonPyPIBSD 3-Clause "New" or "Revised" Licensesecuritysiem
2.7k392
beenuar/AiSOC

Open-source AI-powered Security Operations Center — alert fusion, purple-team drills, agent-assisted triage, MITRE ATT&CK investigation. MIT-licensed, self-hostable.

PythonPyPIMIT Licenseai-securityalert-triage
tryaisoc.com
2.4k251
VictoriaMetrics/VictoriaLogs

Fast and easy to use database for logs, which can efficiently handle terabytes of logs

GoGo ModulesApache License 2.0elasticsearchlogs
docs.victoriametrics.com/victorialogs/
2.2k190
mozilla/MozDef

DEPRECATED - MozDef: Mozilla Enterprise Defense Platform

PythonPyPIMozilla Public License 2.0siempython
2.2k323
sherifabdlnaby/elastdocker

🐳 Elastic Stack (ELK) v9+ on Docker with Compose. Pre-configured out of the box to enable Logging, Metrics, APM, Alerting, ML, and SIEM features. Up with a Single Command.

DockerfileMIT Licenseelkelk-stack
towardsdatascience.com/running-securing-and-deploying-elastic-stack-on-docker-f1a8ebf1dc5b
2.1k339
mthcht/awesome-lists

Awesome Security lists for SOC/CERT/CTI

YARAawesomeMIT Licenseblueteamhacktools
1.9k239
cyb3rxp/awesome-soc

A curated knowledge base to build, run and mature a SOC (including CSIRT).

awesomeCreative Commons Zero v1.0 Universalcertcsirt
1.8k293
matanolabs/matano

Open source security data lake for threat hunting, detection & response, and cybersecurity analytics at petabyte scale on AWS

Rustcrates.ioApache License 2.0awscloud
matano.dev
1.7k123