This is your work, valued
Senior Security Analyst / SOC / Blue teamer / Detection specialist
Microsoft-eventlog-mindmap. Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...
1.1kEVTX-to-MITRE-Attack. Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.
639SIGMA-detection-rules. Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques
440Splunk-input-windows-baseline. Provides an advanced input.conf file for Windows and 3rd party related software with more than 70 different event log mapped to the MITRE Att&CK
100Windows-auditing-baseline. Provides an advanced baseline to implement a secure Windows auditing strategy on Windows OS.
70Windows-WEC-server_auto-deploy. PowerShell scripts for fast Windows Event Collector configuration with Palantir toolset
22Windows-authentication-brutforce-cheatsheet. Assist analyst and threat hunters to understand Windows authentication logs and to analyze brutforce scenarios.
21awesome-event-ids. Collection of Event ID ressources useful for Digital Forensics and Incident Response
14windows-itpro-docs. This is used for contributions to the Windows 10 content for IT professionals on docs.microsoft.com.
3