21 open-source projects similar to mthcht/sigma, ranked by shared indexed features. Tags may describe platforms or build tools rather than the same primary purpose. Check each project’s use case, license, and deployment requirements before treating it as a replacement.
Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It provides a vendor-neutral system for defining security event patterns in YAML, ensuring that detection logic remains portable across different monitoring platforms. The project maintains a curated library of peer-reviewed detection rules that identify threats and compliance violations. This standardized approach allows for the exchange of threat hunting logic and the translation of generic signatures into specific queries for various security information and event management systems
Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that
This repository contains a list of which tools each ransomware gang or extortionist gang uses - As defenders, we should exploit the fact that many of the tools used by these cybercriminals are often reused - We can threat hunt, deploy detections, and block these tools to eliminate the ability of…
A tool matrix for Russian APTs based on the Ransomware Tool Matrix
The Stakeholder-specific Vulnerability Categorization (SSVC) is a system for prioritizing actions during vulnerability management. SSVC aims to avoid one-size-fits-all solutions in favor of a modular decision-making system with clearly defined and tested parts that vulnerability managers can…
This project is a detection-as-code framework providing a library of security monitoring rules and predefined detection content for Elasticsearch data indices. It serves as a threat detection rule library designed to identify malicious activity and attack patterns across diverse data streams in cloud and on-premises environments. The framework implements a detection engineering workflow where rules are defined in YAML and managed as versioned code. It includes a set of command-line utilities for automated rule deployment, metadata searching, and template generation, supported by a Python-base
Community Sigma Rules written by Joe Security for threat hunting in sandboxes, licensed under GPL. For a detailed description about our Sigma rules for Sandboxes please have a look at this Blog Post.
A curated collection of C2 frameworks that leverage legitimate services to evade detection.
LOLESXi is a curated list of living off the land behaviours observed via public reporting.
Welcome to LOLRMM (Living Off the Land Remote Monitoring and Management), a community-driven project that provides a curated list of Remote Monitoring and Management (RMM) tools that could potentially be abused by threat actors. Our mission is to assist security professionals in staying informed…
SIGMA detection rules provides a free set of >350 advanced correlation rules to be used for suspicious hunting activities.
GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems.
All the different files can be found behind a fancy frontend here: https://lolbas-project.github.io (thanks @ConsciousHacker for this bit of eyecandy and the team over at https://gtfobins.github.io/). This repo serves as a place where we maintain the YML files that are used by the fancy frontend.
Sigma-Rule-Repository is a collection of detection rules in Sigma Format. In contrast to other Sigma repositories, this repository contains for every detection rule a testing documentation. The detection rules are sorted based on the Mitre ATT&CK Techniques.
Atomic Red Team is an adversary simulation tool and detection validation suite designed to emulate attacker behaviors. It functions as a security control testing framework that uses a library of portable tests to verify if security monitoring and alerting systems correctly identify specific malicious techniques. The project serves as a MITRE ATT&CK emulation framework, mapping individual test executions to a standardized industry taxonomy of adversary behaviors. This mapping allows for the validation of security controls against the MITRE ATT&CK matrix to identify gaps in detection and respon
Rules generated from our public reports are now directly contributed to the SigmaHQ project.
This project aims to compare and evaluate the telemetry of various EDR products.
``` ██ ██ ██████ ██ ██ ██ ██ ██ ██ █████ ██ ██ ██ ██ ██ ██ ▄▄ ██ ██ ██ ██ ██████ ███████ ▀▀