Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
-
Updated
Sep 5, 2023 - HCL
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Demo for Elastic's Auditbeat and SIEM
Export of Kubernetes Audit logs to Yandex Data Streams (YDS) or Kinesis Data Streams.
Collecting, monitoring, and analyzing Yandex Cloud audit logs in an external SIEM Splunk.
Collecting, monitoring and analyzing audit logs in Yandex Managed Service for Managed Service for Elasticsearch (ELK).
Sentinal capabilities implemented
Deploy ELK platform in Yandex Cloud for analyzing K8s security logs: Audit logs, Policy Engine, Falco.
Export of Kubernetes Audit logs to Yandex Object Storage.
Automated installation of Wazuh SIEM [Indexer, Server and Wazuh Dashboard] and agents with Terraform in Google Cloud Platform
Add a description, image, and links to the siem topic page so that developers can more easily learn about it.
To associate your repository with the siem topic, visit your repo's landing page and select "manage topics."