dfir-orc
Cortex
Our great sponsors
dfir-orc | Cortex | |
---|---|---|
1 | 4 | |
356 | 1,249 | |
2.2% | 2.1% | |
8.9 | 4.9 | |
3 months ago | 3 months ago | |
C++ | Scala | |
GNU Lesser General Public License v3.0 only | GNU Affero General Public License v3.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
dfir-orc
-
Standard artifact gathering script
Looks great! Will dig into that. It looks like French ANSSI's DFIR-ORC. Maybe a good solution.
Cortex
-
Internal Threat Intel Database
TheHive Cortex might come in handy here:https://github.com/TheHive-Project/Cortex
-
Top 20 Open-source tools for every Blue Teamer
TheHive is a scalable 4-in-1 open source and free security incident response platform designed to make life easier for SOCs, CSIRTs, CERTs, and any information security practitioner dealing with security incidents that need to be investigated and acted upon swiftly. Thanks to Cortex, our powerful free and open-source analysis engine, you can analyze (and triage) observables at scale using more than 100 analyzers.
-
Looking for a web script dashboard solution
Basically, I am looking for something a bit like Cortex (screenshot), but for a generic and standalone use.
-
Launch HN: Opstrace (YC S19) – open-source Datadog
Thanks for the correction! You linked to the right Cortex, not to be confused with https://github.com/TheHive-Project/Cortex, haha. https://github.com/cortexproject/cortex is what we talk about. Naming is hard.
What are some alternatives?
TheHive - TheHive: a Scalable, Open Source and Free Security Incident Response Platform
IntelOwl - IntelOwl: manage your Threat Intelligence at scale
awesome-incident-response - A curated list of tools for incident response
Kuiper - Digital Forensics Investigation Platform
tenzir - Open source security data pipelines.
catalyst - Catalyst is an open source SOAR and ticket system that helps to automate alert handling and incident response processes
beagle - Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
ThePhish - ThePhish: an automated phishing email analysis tool
vast - VAST is an experimental compiler pipeline designed for program analysis of C and C++. It provides a tower of IRs as MLIR dialects to choose the best fit representations for a program analysis or further program abstraction.
loki - Like Prometheus, but for logs.
opencti - Open Cyber Threat Intelligence Platform
opstrace - The Open Source Observability Distribution