From 70ea107e23509b21b5aecbed0611724e8ed146c8 Mon Sep 17 00:00:00 2001 From: pe3zx Date: Thu, 13 Dec 2018 14:43:15 +0700 Subject: [PATCH] [Tools][DFIR] SecurityRiskAdvisors/TALR --- README.md | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/README.md b/README.md index 227d06e..31c4ff8 100644 --- a/README.md +++ b/README.md @@ -1316,9 +1316,13 @@ _return-to-libc techniques_ Open Source HIDS SECurity - ptresearch/AttackDetection + ptresearch/AttackDetection The Attack Detection Team searches for new vulnerabilities and 0-days, reproduces it and creates PoC exploits to understand how these security flaws work and how related attacks can be detected on the network layer. Additionally, we are interested in malware and hackers’ TTPs, so we develop Suricata rules for detecting all sorts of such activities. + + SecurityRiskAdvisors/TALR + Threat Alert Logic Repository (TALR) - A public repository for the collection and sharing of detection rules in platform agnostic formats. Collected rules are appended with STIX required fields for simplified sharing over TAXII servers. + refractionPOINT/limacharlie LC is an Open Source, cross-platform (Windows, MacOS, Linux ++), realtime Endpoint Detection and Response sensor. The extra-light sensor, once installed on a system provides Flight Data Recorder type information (telemetry on all aspects of the system like processes, DNS, network IO, file IO etc).