notification-file
dsiem
notification-file | dsiem | |
---|---|---|
1 | 3 | |
0 | 431 | |
- | 0.0% | |
5.6 | 5.7 | |
3 months ago | about 1 month ago | |
Go | Go | |
MIT License | GNU General Public License v3.0 only |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
notification-file
-
I created a notification plugin to write the alerts to a file. Can anyone have a look?
zbalkan/notification-file: CrowdSec plugin that writes the alerts to a file so that any SIEM agent can consume. (github.com)
dsiem
What are some alternatives?
RedELK - Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.
go-stash - go-stash is a high performance, free and open source server-side data processing pipeline that ingests data from Kafka, processes it, and then sends it to ElasticSearch.
velociraptor - Digging Deeper....
docker-elk - The Elastic stack (ELK) powered by Docker and Compose.
RedEye - RedEye is a visual analytic tool supporting Red & Blue Team operations
sysmon-modular - A repository of sysmon configuration modules
adversary_emulation_library - An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.
auditd - Best Practice Auditd Configuration