mfidel@mfidel19May 25, 2025Rainy weekend experiment: anyone else ever thought of using Hayabusa from @SecurityYamato as a poor's man endpoint detection agent for the SOC ? github.comGitHub - mf1d3l/HayabusaToWinEventLog: Hayabusa to the SIEM made easyHayabusa to the SIEM made easy. Contribute to mf1d3l/HayabusaToWinEventLog development by creating an account on GitHub.140
mfidel@mfidel19Dec 1, 2024Splunk4DFIR has now a dedicated dashboard + sigma rules support for GCP Audit logs. Thanks @hackthebox_eu for the MisCloud Sherlock dataset.114227
mfidel@mfidel19Sep 28, 2024Splunk4DFIR has now a dashboard to get quickly started with aws cloudtrail logs.7223
mfidel@mfidel19Jul 21, 2024Splunk4DFIR update: - pre-configured syslog inputs - linux builtin and webserver sigma rules support - web access logs dashboard184