awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descoperă cele mai bune repository-uri open source cu căutare AI.

ExploreazăCăutări recomandateAlternative open-sourceSoftware self-hostedBlogHartă site
ProiectDespreCum realizăm clasamentulPresăServer MCP
LegalConfidențialitateTermeni
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
clong avatar

clong/DetectionLab

0
View on GitHub↗

DetectionLab

DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms.

The project utilizes Ansible for the declarative installation and configuration of domain services and endpoint security tools. It incorporates a browser-based remote access interface via Apache Guacamole to manage laboratory hosts without requiring standalone remote desktop clients.

The environment includes a telemetry pipeline that aggregates Sysmon and Windows Event Logs from multiple hosts into a single analysis point. It further covers endpoint monitoring, network traffic analysis, and data forwarding to security information and event management systems.

Căutare AI

Explorează mai multe repository-uri excelente

Descrie ce ai nevoie în limbaj simplu — AI-ul sortează mii de proiecte open source selectate în funcție de relevanță.

Start searching with AI

Features

  • Windows Domain Detection Labs - Deploys a pre-configured Windows Active Directory environment specifically designed for testing security detection capabilities.
  • Lab Provisioning Automation - Uses Packer and Vagrant to automate the provisioning of multi-machine security laboratory environments.
  • Ansible Playbooks - Provides declarative playbooks to automate the installation of security tools and Active Directory services.
  • Vagrant Multi-Provider Orchestrators - Provides an automation framework using Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms.
  • Windows Domain Detection Testing - Creates a realistic Windows Active Directory environment specifically to verify security alerts and detection rules.
  • Centralized Logging Systems - Aggregates system logs and security telemetry from multiple endpoints into a single central analysis point.
  • Distributed Security Event Aggregation - Centralizes security logs and telemetry from multiple distributed hosts into a single analysis point.
  • Windows Event - Implements a telemetry pipeline that aggregates native Sysmon and Windows Event Logs from multiple hosts.
  • Windows Endpoint Monitoring - Configures system auditing and telemetry tools like Sysmon and OSQuery to track detailed activity across hosts.
  • Browser-Based Remote Desktops - Provides a browser-based remote access interface via Apache Guacamole for interacting with laboratory hosts.
  • Cloud Security Lab Provisioning - Provides infrastructure-as-code provisioning for cloud-based Windows security environments with Active Directory setups.
  • Hypervisor-Specific Lab Provisioning - Implements infrastructure-as-code tooling for provisioning security laboratory environments specifically on ESXi hypervisors.
  • Cross-Hypervisor Orchestration - Abstracts virtualization layers to deploy a single configuration across VirtualBox, VMware, Hyper-V, and cloud platforms.
  • Internal Lab Networks - Creates isolated private networks for virtual lab environments using virtual switches to contain security traffic.
  • Endpoint Auditing Configurations - Implements advanced auditing and transcript logging to capture detailed system and process activity on endpoints.
  • Browser-Based Remote Desktop Clients - Implements a web-based interface via Apache Guacamole for managing laboratory hosts without native RDP clients.
  • Centralized Environment Visibility - Provides a centralized connection system that links all hosts to a single server for unified environment visibility.
  • Browser-Accessible Labs - Offers a centralized web gateway for remote desktop access to all hosts within the security laboratory.
  • System Activity Monitoring - Tracks system processes and events using monitoring tools and custom auditing configurations.
  • Detection Labs - Automated lab setup for security tooling and logging practice.
  • DevSecOps and Automation - Automated lab environment for security tooling.
  • Detection and Hunting Tools - Automated lab environment setup for security tooling and logging.
  • Lab Environments - Automated lab environment with security tooling.
  • Security Tools - Listed in the “Security Tools” section of the Awesome Hacking awesome list.
4,904 stele·1,013 fork-uri·HTML·mit·12 vizualizări

Istoric stele

Graficul istoricului de stele pentru clong/detectionlabGraficul istoricului de stele pentru clong/detectionlab

Întrebări frecvente

Ce face clong/detectionlab?

DetectionLab is a reproducible Windows Active Directory security lab designed for testing detection capabilities. It uses an automation framework based on Vagrant and Packer to provision virtualized networks across multiple hypervisors and cloud platforms.

Care sunt principalele funcționalități ale clong/detectionlab?

Principalele funcționalități ale clong/detectionlab sunt: Windows Domain Detection Labs, Lab Provisioning Automation, Ansible Playbooks, Vagrant Multi-Provider Orchestrators, Windows Domain Detection Testing, Centralized Logging Systems, Distributed Security Event Aggregation, Windows Event.

Care sunt câteva alternative open-source pentru clong/detectionlab?

Alternativele open-source pentru clong/detectionlab includ: stamparm/maltrail — Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network… elastic/beats — Beats is a collection of lightweight, modular agents designed to gather, process, and forward operational telemetry… velocidex/velociraptor — Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and… linuxserver/docker-webtop — This project is a containerized Linux desktop streamer that renders a full operating system interface in a web browser… kunkundi/crossdesk — Crossdesk is a cross-platform remote desktop software used for streaming and controlling remote computers. It consists… lwch/natpass — Natpass is a web-based remote access gateway and orchestrator designed to manage remote server instances, desktop…

Alternative open-source pentru DetectionLab

Proiecte open-source similare, clasificate după numărul de funcționalități comune cu DetectionLab.
  • stamparm/maltrailAvatar stamparm

    stamparm/maltrail

    8,498Vezi pe GitHub↗

    Maltrail is a malicious traffic detection system used for network intrusion detection. It consists of a network intrusion sensor for monitoring interfaces, a threat intelligence aggregator for syncing blacklists, and a detection engine that identifies security threats through signature matching and heuristic attack patterns. The system distinguishes itself through a distributed sensor architecture that collects traffic data from multiple remote probes and forwards events to a central analysis server. It employs heuristic behavioral analysis to identify unknown threats, such as port scanning o

    Pythonattack-detectionintrusion-detectionmalware
    Vezi pe GitHub↗8,498
  • elastic/beatsAvatar elastic

    elastic/beats

    12,630Vezi pe GitHub↗

    Beats is a collection of lightweight, modular agents designed to gather, process, and forward operational telemetry from distributed infrastructure to centralized storage and analysis platforms. These agents function as a distributed data transport layer, decoupling the collection of logs, metrics, and network events from their final delivery destination. By maintaining local state and managing data flow, the system ensures reliable transmission of information across heterogeneous environments. The project distinguishes itself through a modular pipeline architecture that allows for the assemb

    Gofilebeatheartbeatmetricbeat
    Vezi pe GitHub↗12,630
  • velocidex/velociraptorAvatar Velocidex

    Velocidex/velociraptor

    3,769Vezi pe GitHub↗

    Velociraptor is a digital forensics and incident response platform, endpoint detection and response system, and visibility tool. It provides a query engine and remote forensic collector used to hunt for indicators of compromise and perform triage across a fleet of hosts. The system is distinguished by its specialized query language for interrogating host state and parsing binary files. It features a notebook environment that combines markdown documentation with executable query cells to standardize investigative workflows and enable collaborative reporting. The platform covers a wide range o

    Godigital-forensicsendpoint-discoveryendpoint-protection
    Vezi pe GitHub↗3,769
  • linuxserver/docker-webtopAvatar linuxserver

    linuxserver/docker-webtop

    3,936Vezi pe GitHub↗

    This project is a containerized Linux desktop streamer that renders a full operating system interface in a web browser using encoded video streams. It allows for remote access to various Linux distributions and serves as a platform for browser-based application hosting. The system supports GPU acceleration via KVM and direct hardware passthrough to enable low-latency graphics rendering and video encoding. It also features volume mapping for home directory persistence, ensuring that user data and portable applications survive environment updates. Additional capabilities include the creation o

    Shellalpinearchdocker
    Vezi pe GitHub↗3,936
Vezi toate cele 30 alternative pentru DetectionLab→