awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to endgameinc/eql

Open-source alternatives to Endgameinc Eql

30 open-source projects similar to endgameinc/eql, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Endgameinc Eql alternative.

  • airbnb/binaryalertالصورة الرمزية لـ airbnb

    airbnb/binaryalert

    1,450عرض على GitHub↗

    BinaryAlert: Serverless, Real-time & Retroactive Malware Detection.

    Python
    عرض على GitHub↗1,450
  • austin-taylor/flareA

    austin-taylor/flare

    0عرض على GitHub↗
    عرض على GitHub↗0
  • blueteamlabs/sentinel-attackB

    BlueTeamLabs/sentinel-attack

    0عرض على GitHub↗
    عرض على GitHub↗0
  • brimsec/brimB

    brimsec/brim

    0عرض على GitHub↗
    عرض على GitHub↗0
  • clong/detectionlabالصورة الرمزية لـ clong

    clong/DetectionLab

    4,904عرض على GitHub↗

    DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms. The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients. The environment includes a telemetry pipeline that aggre

    HTMLansibledetectiondetectionlab
    عرض على GitHub↗4,904
  • corelight/zeek2esالصورة الرمزية لـ corelight

    corelight/zeek2es

    40عرض على GitHub↗

    A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!

    Python
    عرض على GitHub↗40

بحث بالذكاء الاصطناعي

استكشف المزيد من المستودعات الرائعة

صف ما تحتاجه بلغة بسيطة — وسيقوم الذكاء الاصطناعي بترتيب آلاف المشاريع مفتوحة المصدر المنسقة حسب الصلة.

Find more with AI search
  • cyb3rward0g/helkالصورة الرمزية لـ Cyb3rWard0g

    Cyb3rWard0g/HELK

    3,926عرض على GitHub↗

    HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data. The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and an

    Jupyter Notebook
    عرض على GitHub↗3,926
  • cyb3rward0g/invoke-attackapiC

    Cyb3rWard0g/Invoke-ATTACKAPI

    0عرض على GitHub↗
    عرض على GitHub↗0
  • danielbohannon/revoke-obfuscationD

    danielbohannon/Revoke-Obfuscation

    0عرض على GitHub↗
    عرض على GitHub↗0
  • endgameinc/eqllibE

    endgameinc/eqllib

    0عرض على GitHub↗
    عرض على GitHub↗0
  • endgameinc/varnaالصورة الرمزية لـ endgameinc

    endgameinc/varna

    52عرض على GitHub↗

    Varna: Quick & Cheap AWS CloudTrail Monitoring with Event Query Language (EQL)

    CSS
    عرض على GitHub↗52
  • fireeye/capaالصورة الرمزية لـ fireeye

    fireeye/capa

    6,062عرض على GitHub↗

    capa is a static analysis tool that scans executable files to identify what a program can do, detecting capabilities such as API calls, byte sequences, and structural patterns without executing the code. It supports multiple file formats including PE, ELF, .NET, and shellcode, and can also process runtime behavior traces from sandbox reports generated by CAPE, DRAKVUF, or VMRay. The tool integrates directly with reverse engineering environments through plugins for IDA Pro and Ghidra, allowing analysts to view capability matches and author detection rules within their disassembler of choice. C

    Python
    عرض على GitHub↗6,062
  • foxio-llc/logslashF

    FoxIO-LLC/LogSlash

    0عرض على GitHub↗
    عرض على GitHub↗0
  • intelowlproject/intelowlالصورة الرمزية لـ intelowlproject

    intelowlproject/IntelOwl

    4,605عرض على GitHub↗

    IntelOwl is a threat intelligence platform and security orchestration engine designed to aggregate, analyze, and enrich security observables. It functions as a security incident investigation tool and a threat intelligence aggregator, collecting data on files, domains, and IP addresses from diverse internal and external sources. The system differentiates itself through playbook-based workflow automation, allowing users to define reusable sequences of analysis tasks that trigger subsequent jobs based on prior outputs. It unifies disparate security data into a common schema and utilizes protoco

    Pythoncyber-securitycyber-threat-intelligencecybersecurity
    عرض على GitHub↗4,605
  • jandre/brosqueryJ

    jandre/brosquery

    0عرض على GitHub↗
    عرض على GitHub↗0
  • mitre-attack/attack-navigatorالصورة الرمزية لـ mitre-attack

    mitre-attack/attack-navigator

    2,408عرض على GitHub↗

    Web app that provides basic navigation and annotation of ATT&CK matrices

    TypeScriptcticyber-threat-intelligencecybersecurity
    عرض على GitHub↗2,408
  • mitre-attack/bzarM

    mitre-attack/bzar

    0عرض على GitHub↗
    عرض على GitHub↗0
  • mvelazc0/orianaM

    mvelazc0/Oriana

    0عرض على GitHub↗
    عرض على GitHub↗0
  • netflix/dispatchالصورة الرمزية لـ Netflix

    Netflix/dispatch

    6,385عرض على GitHub↗

    Dispatch is an incident response orchestration platform that automates the coordination of detection, participant assembly, and task tracking across existing communication and project management tools. It provides a web-configurable state machine to manage incident lifecycle transitions, with template-driven incident models that define types, priorities, and severity levels. The platform enforces role-based access control to map user roles to specific actions and data access, while maintaining a database-backed audit trail of all incident events and system changes for compliance and post-incid

    Python
    عرض على GitHub↗6,385
  • olafhartong/threathuntingالصورة الرمزية لـ olafhartong

    olafhartong/ThreatHunting

    1,186عرض على GitHub↗

    A Splunk app mapped to MITRE ATT&CK to guide your threat hunts

    dfirmitre-attacksplunk
    عرض على GitHub↗1,186
  • powershellmafia/cimsweepالصورة الرمزية لـ PowerShellMafia

    PowerShellMafia/CimSweep

    658عرض على GitHub↗

    CimSweep is a suite of CIM/WMI-based tools that enable the ability to perform incident response and hunting operations remotely across all versions of Windows.

    PowerShell
    عرض على GitHub↗658
  • redhuntlabs/redhunt-osالصورة الرمزية لـ redhuntlabs

    redhuntlabs/RedHunt-OS

    1,316عرض على GitHub↗

    Virtual Machine for Adversary Emulation and Threat Hunting

    عرض على GitHub↗1,316
  • sans-blue-team/deepbluecliالصورة الرمزية لـ sans-blue-team

    sans-blue-team/DeepBlueCLI

    2,404عرض على GitHub↗

    DeepBlueCLI - a PowerShell Module for Threat Hunting via Windows Event Logs

    PowerShell
    عرض على GitHub↗2,404
  • security-onion-solutions/security-onionالصورة الرمزية لـ Security-Onion-Solutions

    Security-Onion-Solutions/security-onion

    3,123عرض على GitHub↗

    Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

    عرض على GitHub↗3,123
  • splunk/saloالصورة الرمزية لـ splunk

    splunk/salo

    92عرض على GitHub↗

    Synthetic Adversarial Log Objects (SALO) is a framework for the generation of log events without the need for infrastructure or actions to initiate the event that causes a log event. The purpose of this framework is to allow security practitioners, data scientists, and researchers the ability to…

    Python
    عرض على GitHub↗92
  • strackvibes/nrd-dbS

    StrackVibes/NRD-db

    0عرض على GitHub↗
    عرض على GitHub↗0
  • supercowpowers/zatS

    SuperCowPowers/zat

    0عرض على GitHub↗
    عرض على GitHub↗0
  • tenzir/threatbusالصورة الرمزية لـ tenzir

    tenzir/threatbus

    270عرض على GitHub↗

    🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.

    Python
    عرض على GitHub↗270
  • tenzir/vastالصورة الرمزية لـ tenzir

    tenzir/vast

    742عرض على GitHub↗

    Tenzir is the data pipeline engine for security teams.

    C++
    عرض على GitHub↗742
  • unfetter-analytic/unfetterU

    unfetter-analytic/unfetter

    0عرض على GitHub↗
    عرض على GitHub↗0