Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It provides a vendor-neutral system for defining security event patterns in YAML, ensuring that detection logic remains portable across different monitoring platforms. The project maintains a curated library of peer-reviewed detection rules that identify threats and compliance violations. This standardized approach allows for the exchange of threat hunting logic and the translation of generic signatures into specific queries for various security information and event management systems
Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides a structured way to define malicious behavior and detection logic independently of any specific backend technology, acting as a translation engine that maps generic event fields and correlation logic to the proprietary query languages of security data lakes and SIEM platforms. The project features a plugin-based multi-backend query generator that exports security detections into various database and log management formats. It also includes a threat framework mapping tool that
This project is a machine learning educational curriculum and learning platform delivered through interactive Jupyter Notebooks. It serves as a comprehensive guide for mastering the Python data science toolkit, providing structured tutorials for numerical computing, tabular data manipulation, and statistical visualization. The curriculum includes specific implementation guides for Scikit-Learn and a practical course on TensorFlow for constructing, training, and deploying neural networks and computer vision models. It covers the end-to-end process of building predictive models, from initial pr
This repository contains a list of which tools each ransomware gang or extortionist gang uses - As defenders, we should exploit the fact that many of the tools used by these cybercriminals are often reused - We can threat hunt, deploy detections, and block these tools to eliminate the ability of…
GTFOBins is a curated list of Unix binaries that can be used to bypass local security restrictions in misconfigured systems.
Principalele funcționalități ale mthcht/gtfobins.github.io sunt: Data Manipulation, Detection Engineering.
Alternativele open-source pentru mthcht/gtfobins.github.io includ: sigmahq/sigma — Sigma is a suite of tools for defining generic log signatures and translating them for multiple backends. It provides… neo23x0/sigma — Sigma is a generic SIEM signature format and log event pattern standard used to describe malicious activity. It… mrdbourke/zero-to-mastery-ml — This project is a machine learning educational curriculum and learning platform delivered through interactive Jupyter… bushidouk/ransomware-tool-matrix — This repository contains a list of which tools each ransomware gang or extortionist gang uses - As defenders, we… cyb3rxp/awesome-soc. certcc/ssvc — The Stakeholder-specific Vulnerability Categorization (SSVC) is a system for prioritizing actions during vulnerability…