blue-teaming-with-kql
Repository with Sample KQL Query examples for Threat Hunting (by ashwin-patil)
SIEM
SIEM Tactics, Techiques, and Procedures (by TonyPhipps)
blue-teaming-with-kql | SIEM | |
---|---|---|
1 | 1 | |
187 | 513 | |
- | - | |
10.0 | 6.3 | |
over 1 year ago | 3 days ago | |
MIT License | GNU General Public License v3.0 only |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
blue-teaming-with-kql
Posts with mentions or reviews of blue-teaming-with-kql.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2023-01-08.
-
Microsoft Sentinel - the whys of KQL
Also: - https://threathunt.blog/tag/kql/ - MDE-specific: https://learn.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query-language?view=o365-worldwide - https://github.com/ashwin-patil/blue-teaming-with-kql
SIEM
Posts with mentions or reviews of SIEM.
We have used some of these posts to build our list of alternatives
and similar projects.
-
Best practices for SIEM?
This is a good start IMO
What are some alternatives?
When comparing blue-teaming-with-kql and SIEM you can also consider the following projects:
awesomekql - Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs
WELA - WELA (Windows Event Log Analyzer): The Swiss Army knife for Windows Event Logs! ゑ羅(ウェラ)
hunt-searchengine
threathunting-spl - Splunk code (SPL) for serious threat hunters and detection engineers.
hayabusa - Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.
Threat_Model_Examples - Collection of Threat Models
slides-talks - My own cybersecurity research talks/slides