Dorothy Logo

Dorothy

0
Free
Visit Website

Created by David French (@threatpunter) at Elastic Security, Dorothy is a tool designed to help security teams test their monitoring and detection capabilities for their Okta environment. It offers modules to simulate attacker actions and security audit actions in an Okta environment, mapped to relevant MITRE ATT&CK® tactics like persistence, defense evasion, and discovery. Elastic Security's free detection rules for Okta can be found in their detection-rules repository. It is recommended to use Dorothy in a test environment to avoid any impact on the production environment.

FEATURES

ALTERNATIVES

A repository to aid Windows threat hunters in looking for common artifacts.

Open Source Intelligence solution for threat intelligence data enrichment and quick analysis of suspicious files or malware.

Signature-based YARA rules for detecting and preventing threats within Linux, Windows, and macOS systems.

A tool for tracking, scanning, and filtering yara files with distributed scanning capabilities.

Threat intelligence platform providing real-time threat data and insights.

A tool for navigating and annotating ATT&CK matrices with the ability to define custom layers for specific views.

Freely available network IOCs for monitoring and incident response

ElectricEye is a multi-cloud, multi-SaaS Python CLI tool for Asset Management, Security Posture Management & Attack Surface Monitoring.

PINNED