
siem
Here are 120 public repositories matching this topic...
Someone should map publicly available EVTX samples to Sigma rules. This would enable us to automatically test the correctness of generated queries.
Known security-related EVTX repositories:
Feel free to extend the list.
Mapping should be:
Sigma rule -> Repository/EVTX ( -> expected matched
-
Updated
Oct 10, 2020 - CSS
-
Updated
Aug 28, 2020 - HCL
-
Updated
Oct 12, 2020 - Java
-
Updated
Oct 6, 2020
-
Updated
Oct 7, 2020 - PowerShell
-
Updated
Sep 14, 2020 - Go
-
Updated
Oct 8, 2020 - C#
-
Updated
Oct 12, 2020 - C++
-
Updated
Jul 1, 2020
-
Updated
Oct 31, 2018
-
Updated
Jun 5, 2020 - Python
-
Updated
Sep 25, 2020 - Python
-
Updated
Apr 20, 2017
-
Updated
Nov 5, 2019 - PowerShell
-
Updated
Jun 9, 2020 - Go
-
Updated
Dec 15, 2019 - Python
-
Updated
May 24, 2020 - Shell
Improve this page
Add a description, image, and links to the siem topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the siem topic, visit your repo's landing page and select "manage topics."