HELK is a containerized security information and event management environment and threat hunting platform. It provides a security-focused deployment of the ELK stack, combining Elasticsearch, Logstash, and Kibana into a specialized platform for investigating logs and discovering hidden patterns in network and system security data. The project functions as a security data science suite, integrating interactive computational notebooks and distributed processing tools to run machine learning and graph analytics on security logs. This allows for the identification of hidden attack patterns and an
Indicators of Compromises (IOC) of our various investigations
Repository containing IOCs, CSV and MISP JSON from our blogs
Malware Configuration And Payload Extraction
Collecting & Hunting for IOCs with gusto and style
الميزات الرئيسية لـ rastrea2r/rastrea2r هي: Yara Rule Collections, Incident Response Frameworks, Malware Analysis, Threat Hunting Operations.
تشمل البدائل مفتوحة المصدر لـ rastrea2r/rastrea2r: eset/malware-ioc — Indicators of Compromises (IOC) of our various investigations. viper-framework/viper — Binary analysis and management framework. advanced-threat-research/iocs — Repository containing IOCs, CSV and MISP JSON from our blogs. cyb3rward0g/helk — HELK is a containerized security information and event management environment and threat hunting platform. It provides… kevoreilly/capev2 — Malware Configuration And Payload Extraction. yara-rules/rules — This project is a community-curated repository of YARA rules used to detect malware, webshells, and other malicious…