PagerDuty's Incident Response Documentation.
created at Nov. 28, 2016, 5:58 p.m.
StreamAlert is a serverless, realtime data analysis framework which empowers you to ingest, analyze, and alert on data from any environment, using datasources and alerting logic you define.
created at Jan. 22, 2017, 1:10 a.m.
Sysmon configuration file template with default high-quality event tracing
created at Feb. 1, 2017, 6:49 p.m.
CLI utility and Python module for analyzing log files and other data.
created at Feb. 19, 2017, 8:31 p.m.
A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.
created at March 28, 2017, 3:07 a.m.
"Evolving AppCompat/AmCache data analysis beyond grep"
created at April 2, 2017, 6:11 p.m.
PowerSponse is a PowerShell module focused on targeted containment and remediation during incident response.
created at Sept. 14, 2017, 9:15 a.m.
"Security Incidents In A Box!" A modular, menu-driven, cross-platform tool for building customized, time-delayed, distributed security events. Easily create custom event chains for Blue- & Red Team drills and sensor / alert mapping. Red Teams can create decoy incidents, distractions, and lures to support and scale their operations. Build event sequences ("narratives") to simulate realistic scenarios and generate corresponding network and filesystem artifacts.
created at Oct. 5, 2017, 11:44 p.m.
Small and highly portable detection tests based on MITRE's ATT&CK.
created at Oct. 11, 2017, 5:23 p.m.
An information security preparedness tool to do adversarial simulation.
created at Nov. 1, 2017, 9:24 p.m.
Investigate malicious Windows logon by visualizing and analyzing Windows event log
created at Nov. 24, 2017, 6:07 a.m.