DShield Sensor Log Collection with ELK
-
Updated
Oct 5, 2026 - Shell
DShield Sensor Log Collection with ELK
Self-hosted AI-assisted CTI-to-detection workbench for ATT&CK mapping, IOC/CVE intelligence, Threat Radar, malware triage, Attack Simulation, and SIEM validation.
OWASP Python framework for automated STRIDE threat modeling as code — MITRE ATT&CK mapping, D3FEND mitigations, Attack Flow, CAPEC, severity scoring, SVG/HTML reports & MITRE Navigator layers. DevSecOps & CI/CD ready.
A Python script to generate MITRE ATT&CK Navigator layers from TTPs
MCP server that maps Tenable Security Center findings to the MITRE ATT&CK framework, then lets you ask your LLM (Claude Code) to analyze exposure by specific tactic or technique in plain language — and optionally open the results as an interactive ATT&CK Navigator matrix in a local web viewer.
Purple-team detection-engineering lab with ML-assisted Sigma/YARA rule generation, and coverage/FP/evasion scoring.
Tactics and Techniques used by Iraninan APT groups for MITRE
Proactive threat hunting methodologies, detection engineering, MITRE ATT&CK mappings, and adversary behavior analysis for cyber defense
Browser-based MITRE ATT&CK analyst workbench (Angular 19) — 9 routed workspaces, 31 heatmap modes, command palette, MISP/OpenCTI integrations, and grounded threat-intel/exposure/detection/compliance data. Static SPA, no backend.
Python toolchain that maps MITRE ATT&CK techniques to D3FEND defenses and builds ATT&CK Navigator coverage layers from STIX data.
Detection-as-code pipeline with measured precision/recall against OTRF captures. 20 Sigma rules, multi-SIEM (SPL/EQL/KQL), ATT&CK coverage, two logsource baselines. By Aadarsh Kadam.
A Zero Trust overlay network in Flask with detection-as-code , every service behind one gate, every request logged with trace_id correlation, three Sigma rules validated against atomic ATT&CK attacks.
A utility to extract MITRE ATT&CK Techniques from a file, pdf, or URL and create ATT&CK Navigator layer from the result.
Deterministic .NET workbench for synthetic security-alert triage: ATT&CK mapping, safe dry-run playbooks, detection testing against fixtures, and an HTTP API — CLI + xUnit tests.
Indian Socio-technical Cyber Matrix: an open-source, ATT&CK-style framework of the TTPs cybercrime syndicates use against Indian citizens, FIN/NFIN taxonomy, every technique cross-referenced to MITRE ATT&CK.
Claimed vs detection-backed MITRE ATT&CK coverage on real data: official CIS v8, NIST 800-53 (+800-53B baselines) and CTID framework mappings joined with SigmaHQ rules and their log sources; cross-framework auto-mapping, SPOFs, set-cover recommender, heatmap UI
Evidence-based Cyber Threat Intelligence (CTI) investigation of a multi-domain recruitment fraud campaign using OSINT, MITRE ATT&CK, STIX, MISP, and ATT&CK Navigator.
To associate your repository with the attack-navigator topic, visit your repo's landing page and select "manage topics."