We are a security team with 20+ years of ethical hacking, and we've defended over 2 million attacks with Blumira. Ask Us Anything.

This page summarizes the projects mentioned and recommended in the original post on /r/cybersecurity

Our great sponsors
  • WorkOS - The modern identity platform for B2B SaaS
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • SaaSHub - Software Alternatives and Reviews
  • sigma

    Main Sigma Rule Repository

  • In general I'm going to take the somewhat oppositional standpoint and say that all of these tools are damned similar in the grand scheme of it all. I think if you have the time you're better off implementing Sysmon across your entire Windows environment and utilize Sigma or similar to quickly improve your behavior detections and instead depend on your EDRs to handle known signature-based detections.

  • dfirtrack

    DFIRTrack - The Incident Response Tracking Application

  • WorkOS

    The modern identity platform for B2B SaaS. The APIs are flexible and easy-to-use, supporting authentication, user identity, and complex enterprise features like SSO and SCIM provisioning.

    WorkOS logo
  • TheHive

    TheHive: a Scalable, Open Source and Free Security Incident Response Platform

  • https://thehive-project.org/ - of course :)

  • Wazuh

    Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

  • https://github.com/wazuh/wazuh - Elastic is a PITA to grow but works well for viz

  • grr

    GRR Rapid Response: remote live forensics for incident response

  • https://github.com/google/grr - great as a homegrown agent

  • velociraptor

    Digging Deeper....

  • https://github.com/Velocidex/velociraptor - purchased recently but still a great tool

NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts