From 11f65cb01615666f0b7043e7c72924f2722bac6e Mon Sep 17 00:00:00 2001 From: pe3zx Date: Sun, 31 Mar 2019 22:48:17 +0700 Subject: [PATCH] [Tools][DFIR] Security Onion --- README.md | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/README.md b/README.md index 2086c1a..29c364a 100644 --- a/README.md +++ b/README.md @@ -1391,6 +1391,10 @@ _return-to-libc techniques_ salesforce/bro-sysmon Bro-Sysmon enables Bro to receive Windows Event Logs. This provide a method to associate Network Monitoring and Host Monitoring. The work was spurred by the need to associate JA3 and HASSH fingerprints with the application on the host. The example below shows the hostname, Process ID, connection information, JA3 fingerprints, Application Path, and binary hashes. + + Security Onion + Peel back the layers of your enterprise + SecurityRiskAdvisors/TALR Threat Alert Logic Repository (TALR) - A public repository for the collection and sharing of detection rules in platform agnostic formats. Collected rules are appended with STIX required fields for simplified sharing over TAXII servers.