Security-operation-book目前已覆盖106个TID,326个场景。主要涵盖Web、Windows AD、Linux,涉及ATT&CK技术、模拟测试、检测思路、检测所需数据源等。
Web_Attck检测规则为Suricata、Sigma两种格式,端点检测规则为Sigma格式为主。
- Security-Datasets
- OTRF/OSSEM
- Windows_Sysmon
- HELK
- threathunters-io/laurel
- Zeek
- Suricata
- Microsoft事件日志思维导图
- Windows事件收集器部署工具
- SELKS
- Sigma (by Neo23x0)
- Elastic_detection-rules
- elastic-prebuilt-rules
- Splunk security_content
- Splunk-detections
- Atomic Blue Detections
- Detecting ATT&CK techniques & tactics for Linux (by Kirtar22)
- ThreatHunter-Playbook
- Threat Hunter Playbook
- 有关网络安全的所有最佳链接和资源
- Atomic Red Team (by Red Canary)
- Purple-team-attack-automation
- Mitre/caldera
- ......