Skip to content

securesynapse/SOC

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

34 Commits
 
 
 
 

Repository files navigation

Creating a SOC with OSS
This Repo is a collection of scripts to install some of the most critical OSS available for Security Operation Centers. Links have also been provided to the tools. I have found through my experience that one of the largest barriers to the implementation of some of these fantastic tools is the challenges that are presented when attempting to install and configure them.

If you think about your SOC ecosystem you need a number of tools to assist with your operations.

Knowledge Management/TIP:

Detecting Threats:

Centralized Alert Storage:

Intelligence Report Acquisition:

IOC Enrichment:

  • Maltego - I know it's not free; but it's super cheap

Forensics:

  • GRR - Allows the ability to acquire live images from remote hosts
  • SANS SIFT - Live forensic CD for image acquisition an analysis
    • dd - Forensic image acquisition (linux only and included in SIFT)
  • Sleuthkit - Lots of great tools although I use most for timeline analysis
  • Redline - Analyzing Forensic images. Simple interface; easy for junior members to use
  • Volatility - Awesome for analyzing memory

Threat Hunting

  • HELK - Needs a fairly beefy system for testing

Malware Analysis:

Malware Repository:

Security Orchestration:

Vulnerability Management:

Rule Validation - MITRE ATT&CK Framework (Red team activities)

Software Inventory:

Interesting Projects:

  • RITA - Real Intelligence Threat Analytics

Please email me with recommendations on free OSS that I've missed which you feel should be on the list. securesynapse@gmail.com

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published