EventList
by miriamxyra
EventList
AI summary
Hunting query generator
An automation tool that integrates Microsoft Security Baselines and MITRE ATT&CK to generate hunting queries for security operation centers.
- stars
- 370
- forks
- 40
- watching
- 33
Similar projects
Found by comparing what the projects do, not just their names.
Security queries
Provides KQL queries for hunting and detection in security logs
Threat hunter
Automates scanning of publicly hosted pasted data against Yara rules to identify potential security or research threats.
Query tool
A web-based Yara query accelerator for malware analysis and digital forensics
Threat Hunting Platform
A collection of tools and resources for threat hunters to identify and respond to cyber threats.
Threat hunt workflow builder
A language and runtime framework for building reusable, composable threat hunting workflows using Python.
Malware scanner
Helps Threat Intelligence researchers hunt for new malware by efficiently scanning large collections of files with Yara rules
Malware detection toolkit
A collection of resources and tools for detecting and preventing malicious activity on Windows systems.
Event log analyzer
A tool to analyze Windows event logs for signs of APT attacks and malware activity.
Endpoint Scanner
A Powershell Threat Hunting Module designed to scan and survey remote endpoints for indicators of compromise or comprehensive system information.
Threat hunter
An aggregator tool for querying multiple services to gather threat intelligence data.
Malware toolkit
A collection of threat intelligence resources and tools for analyzing APT malware
Domain scanner
Tools and rules for detecting malicious domain calls in endpoint malware
Signature generator
Generates Yara signatures for identifying malware code similarities
Threat detection queries
Provides Splunk queries to detect vulnerability exploitation attempts and subsequent compromise, including threat hunting for MITRE ATT&CK TTPs
Threat Hunting App
A Splunk application designed to guide threat hunts by mapping investigations to the MITRE ATT&CK framework