DetectionLab VS APTnotes

Compare DetectionLab vs APTnotes and see what are their differences.

DetectionLab

Automate the creation of a lab environment complete with security tooling and logging best practices (by clong)

APTnotes

Various public documents, whitepapers and articles about APT campaigns (by kbandla)
InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
DetectionLab APTnotes
31 5
4,476 3,410
- -
4.4 3.1
about 1 year ago 4 months ago
HTML
MIT License -
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

DetectionLab

Posts with mentions or reviews of DetectionLab. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2023-01-25.

APTnotes

Posts with mentions or reviews of APTnotes. We have used some of these posts to build our list of alternatives and similar projects. The last one was on 2022-10-13.
  • Ask HN: What Happened with the Grugq Article?
    1 project | news.ycombinator.com | 23 Aug 2023
    >with case studies and getting as niche on specific things as possible.

    Then definitely you can touch on APT marketplace, unlike the usual zeroday ones, those are -as the name implies, advanced, and mostly are state sponsored, you can find some of these in this sheet [1], or other sources [2] or older ones [3]. Now, for other zero day exploits, you can dig into your typical threat intelligence feeds to have an idea, some of these are daily updated [4] [5] [6] among a lot more of other resources, there are also underground databases for zero day and even APT updated as of yesterday, and also online marketplaces for those where you can buy/sell compromised RDP servers / webmail / cPanels / etc., or even services like smtp-sms for phishing among others, unfortunately, I can’t and won’t list any of these in here for obvious reasons, however, if you dig a little deeper definitely you will find something, just don’t use the usual search engines and normal channels, and get the usual security precautions like sandbox/vpns/etc. when access any of these sites, preferably in an isolated OS too.

    And thanks, not expert enough for sure!

    [1] https://docs.google.com/spreadsheets/u/1/d/1H9_xaxQHpWaa4O_S...

    [2] https://gist.github.com/Neo23x0/c4f40629342769ad0a8f3980942e...

    [3] https://github.com/kbandla/APTnotes

    [4] https://bazaar.abuse.ch/browse/

    [5] https://www.exploitalert.com/browse-exploit.html

    [6] https://threatfox.abuse.ch/browse/

  • Seeking Datasets on Malware
    1 project | /r/cybersecurity | 9 Jun 2023
    I trained up this repo in my privateGPT - https://github.com/kbandla/APTnotes
  • Le Burkina Faso
    2 projects | /r/france | 13 Oct 2022
  • Cybersecurity Repositories
    71 projects | /r/netsecstudents | 31 May 2022
    APT Notes
  • Les ressortissants russes en France reçoivent en ce moment sur leurs numéros de téléphone russe des demandes pour l'enrôlement dans l'armée en vue de la guerre avec l'Ukraine
    1 project | /r/france | 20 Feb 2022

What are some alternatives?

When comparing DetectionLab and APTnotes you can also consider the following projects:

DetectionLabELK - DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.

data - APTnotes data

vulnerable-AD - Create a vulnerable active directory that's allowing you to test most of the active directory attacks in a local lab

ThreatHunter-Playbook - A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more efficient.

security-onion - Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management

awesome-ctf - A curated list of CTF frameworks, libraries, resources and softwares

Adaz - :wrench: Deploy customizable Active Directory labs in Azure - automatically.

osx-and-ios-security-awesome - OSX and iOS related security tools

DVWA - Damn Vulnerable Web Application (DVWA)

awesome-adversarial-machine-learning - A curated list of awesome adversarial machine learning resources

HELK - The Hunting ELK

awesome-iocs - A collection of sources of indicators of compromise.