This repository provides a baseline template for organizations deploying osquery in a production environment, including query packs tailored to specific environments such as unwanted-chrome-extensions and windows-attacks, emphasizing careful consideration of datasets and use-cases for optimal osquery operation.
FEATURES
EXPLORE BY TAGS
SIMILAR TOOLS
Web-based tool for incident response with easy local installation using Docker.
Open-source, free, and scalable cyber threat intelligence and security incident response solution with improved performance and new features.
Open-source security automation platform for automating security alerts and building AI-assisted workflows.
Cortex XSOAR is a comprehensive SOAR platform that automates and standardizes security processes for faster response times and increased team productivity.
Dispatch helps manage security incidents by integrating with existing tools and automating incident response tasks.
AWS Community repository of custom Config rules with instructions for leveraging and developing AWS Config Rules.
A collection of structured incident response playbook battle cards that provide prescriptive countermeasures and procedures for combating cyber threats and attacks during security incidents.
Request Tracker for Incident Response (RTIR) is a tool for incident response teams to manage incident reports, correlate data, and facilitate communication.
A human risk management platform that identifies, assesses, and mitigates security risks associated with employee behavior through monitoring, targeted interventions, and comprehensive reporting.
PINNED

Mandos
Fractional CISO service that helps B2B companies implement security leadership to win enterprise deals, achieve compliance, and develop strategic security programs.

Checkmarx SCA
A software composition analysis tool that identifies vulnerabilities, malicious code, and license risks in open source dependencies throughout the software development lifecycle.

Orca Security
A cloud-native application protection platform that provides agentless security monitoring, vulnerability management, and compliance capabilities across multi-cloud environments.

DryRun
A GitHub application that performs automated security code reviews by analyzing contextual security aspects of code changes during pull requests.