sentinel-attack

Threat hunter

A tool to quickly deploy a threat hunting capability on Azure Sentinel using Sysmon and MITRE ATT&CK

Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK

GitHub

1k stars
72 watching
209 forks
last commit: almost 2 years ago
Linked from 1 awesome list

azureazure-sentinelblue-teamcybersecuritydetectionkqlloggingmitre-attacksecurity-toolssiemsysmonsysmon-configterraform-azurethreat-huntingworkbooks

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
a3sal0n/cyberthreathuntingA collection of tools and resources for threat hunters to identify and respond to cyber threats.861
miladaslaner/threathuntA PowerShell repository to simulate and train threat hunting skills without malicious files.134
ninoseki/mihariAn aggregator tool for querying multiple services to gather threat intelligence data.870
matamorphosis/scrummageA platform for searching and analyzing publicly available online data to detect potential security threats515
aboutsecurity/rastrea2rA tool for hunting and tracking Internet of Things (IoT) security threats by collecting and analyzing indicators of compromise (IOCs)116
sbousseaden/slidesCollection of resources and concepts for threat hunting and detection engineering.372
sapphirex00/threat-huntingA collection of threat intelligence resources and tools for analyzing APT malware257
gossithedog/threathuntingTools and rules for detecting malicious domain calls in endpoint malware570
mandiant/mandiant-azure-ad-investigatorA PowerShell module designed to detect potential security threats in Azure AD environments617
thalesgroup-cert/watcherAutomated platform for discovering and analyzing cybersecurity threats targeting an organization869
otrf/threathunter-playbookA community-driven project providing shared detection logic and resources for threat hunting4,049
threathuntingproject/threathuntingAn informational repository providing resources and knowledge for detecting adversaries in IT environments.1,726
rabbitstack/fibratusDetects and mitigates advanced threat tradecraft by analyzing system events and behavior patterns2,246
olafhartong/threathuntingA Splunk application designed to guide threat hunts by mapping investigations to the MITRE ATT&CK framework1,141
infocyte/pshuntA Powershell Threat Hunting Module designed to scan and survey remote endpoints for indicators of compromise or comprehensive system information.280