The Exabeam Security Operations Platform applies AI and automation to security operations workflows to deliver the industry's most effective offerings for threat detection, investigation, and response (TDIR). With 680+ product integrations, 9500+ log parsers, and 10+ years of data storage, it provides a future-proof platform for cloud-native architecture, modern log management, and powerful behavioral analytics. The platform automates and modernizes TDIR workflows, streamlining operations and providing a comprehensive risk-based threat analysis. The platform's features include: * Cloud-native architecture built on Google Cloud * Rapid data ingestion, hyper-fast query performance, and powerful behavioral analytics and AI * 680+ product integrations * 9500+ log parsers * 10+ years of data storage * 195+ pre-built correlation rules * Automated investigation experience for streamlined TDIR workflows Exabeam helps the world's leading organizations fight what they can't see with faster, more accurate, and repeatable threat detection, investigation, and response (TDIR).
FEATURES
SIMILAR TOOLS
PowerGRR is a PowerShell module for the GRR API, allowing automation and scripting for incident response and remote live forensics.
Tool to bypass endpoint solutions blocking known 'malicious' signed applications by obtaining valid signed files with different hashes.
A defense-in-depth security automation and monitoring framework utilizing threat intelligence, machine learning, and serverless technologies.
Incident response framework focused on remote live forensics
Cortex XSOAR is a comprehensive SOAR platform that automates and standardizes security processes for faster response times and increased team productivity.
DFIRTrack is an open source web application focused on incident response for handling major incidents with many affected systems, tracking system status, tasks, and artifacts.
A Sysmon configuration file template with detailed explanations and tutorial-like features.
Open source application to instantly remediate common security issues through the use of AWS Config.
Dispatch helps manage security incidents by integrating with existing tools and automating incident response tasks.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.