Automate the creation of a lab environment complete with security tooling and logging best practices
-
Updated
May 31, 2022 - HTML
{{ message }}
Automate the creation of a lab environment complete with security tooling and logging best practices
A flexible control server for osquery fleets
Open source device management, built on osquery.
A repository for using osquery for incident detection and response
Zentral is an open-source solution for infrastructure monitoring and endpoint event stream processing. It provides build-in orchestration of macOS security components (Santa, Osquery, et-al.), event correlation and event management. It consolidates its features with various data store backends (ElasticStack, Azure Log Analytics, Splunk, et-al.).
DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.
Osquery launcher, autoupdater, and packager
Hubble is a modular, open-source security compliance framework. The project provides on-demand profile-based auditing, real-time security event notifications, alerting, and reporting. HubbleStack is a free and open source project made possible by Adobe. https://github.com/adobe
Fast and efficient osquery management
Threat Hunting & Incident Investigation with Osquery
SIAC is an enterprise SIEM built on open-source technology.
To switch between hosts you use the .connect command which means that it issues the validation query to pull hosts from the remote machine again.
Ideally this shouldn't happen as we already know what they are.
A simple threat hunting tool based on osquery, Salt Open and Cymon API
kubequery powered by Osquery
Manage, monitor and improve your cyber security posture.
Fleet's lightweight osquery runtime and autoupdater.
A starter-kit for a source-controlled, CLI-based osquery management workflow.
Community Edition of the PolyLogyx Endpoint Security Platform; An open source and extensible platform to manage and monitor endpoints, based on osqery agent
Add a description, image, and links to the osquery topic page so that developers can more easily learn about it.
To associate your repository with the osquery topic, visit your repo's landing page and select "manage topics."