Skip to content

Infinit3i/Defensive-Rules

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Defensive-Rules

Detections Cover






Twitter Follow Chat on Discord

This repository is a curated collection of detection rules authored by Matthew Iverson, organized first by rule type (Sigma or Splunk), and then by data source (Windows, Syslog, Zeek). The goal is to provide defenders with a centralized, modular resource for quickly identifying and deploying high-fidelity detections across multiple log types and platforms. While these rules are currently untested, they are based on real-world use cases, mapped to MITRE ATT&CK, and written with clarity and customization in mind.

Sigma

- windows
- syslog
- zeek

Splunk

- windows
- syslog
- zeek

NONE OF THESE ARE TESTED YET

Splunk

  • Change index to match your index

About

sigma, spl rules

Topics

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Contributors 2

  •  
  •