The EQL Analytics Library (eqllib) is a library of event-based analytics written in EQL to detect adversary behaviors identified in MITRE ATT&CK. It provides rules in EQL, KQL, or Lucene for the Elastic Stack, now integrated into the Detection Engine of Kibana.
A summary of the threat modeling posts and final thoughts on the process
A repository to aid Windows threat hunters in looking for common artifacts.
A collection of APT and cybercriminals campaigns with various resources and references.
Aggregates security threats from online sources and outputs to various formats.
Container of 200 Windows EVTX samples for testing detection scripts and training on DFIR.
Utilize Jupyter Notebooks to enhance threat hunting capabilities by focusing on different threat categories or stages.
A collection of Yara rules licensed under the DRL 1.1 License.
Fabric Platform is a cybersecurity reporting solution that automates and standardizes report generation, offering a private-cloud platform, open-source tools, and community-supported templates.
Stay ahead in cybersecurity. Get the week's top cybersecurity news and insights in 8 minutes or less.
Wiz Cloud Security Platform is a cloud-native security platform that enables security, dev, and devops to work together in a self-service model, detecting and preventing cloud security threats in real-time.
Adversa AI is a cybersecurity company that provides solutions for securing and hardening machine learning, artificial intelligence, and large language models against adversarial attacks, privacy issues, and safety incidents across various industries.