Open-source asset inventory — turn scattered, contradictory tool data into one reliable inventory, then chat with it using the LLM of your choice. Tagging, posture rules, and alerting built in.
-
Updated
Aug 7, 2026 - Python
Open-source asset inventory — turn scattered, contradictory tool data into one reliable inventory, then chat with it using the LLM of your choice. Tagging, posture rules, and alerting built in.
This repository contains DEVO SIEM use cases covering multiple security domains and technologies. Each use case is designed to detect specific threats, suspicious activities, or policy violations with detailed response playbooks and MITRE ATT&CK mappings.
Botnet Radar — host-level anomaly detection for defensive operators. Watches packet-rate spikes and distributed UDP patterns to surface early signs of botnet behavior and DDoS activity. Offense-driven defense. Built by Red Specter.
Detection engineering project focused on Sysmon tuning, noise reduction, and integrating endpoint telemetry into Splunk to improve visibility and alert fidelity.
Policy-bound defensive security tool: ranks which exposure to harden first and proves why with sourced evidence; fixture-only validation, SIEM/ticket handoffs. Pure-Python core + React console.
Automatically downloads, parses, and synchronizes Sigma rules into various SIEM formats.
Plugin-driven framework for auditing AI model behavior across providers and deployment targets. Run the same backdoor scan against OpenAI, Anthropic, local PyTorch models, or HuggingFace without changing the scanner. Push findings to Splunk, Elastic, Datadog, or Sentinel.
Advanced File Integrity Monitoring (FIM) system with real-time alerts, AI-powered analysis, SIEM integration, and comprehensive security monitoring.
PurpleForge is a FastAPI-based adversary simulation and threat‑intelligence platform that transforms red-team technique execution into collaborative exercises, measurable detection coverage, and executive-level risk reporting for multi‑tenant environments.
Step-by-step guide: Cisco Secure Workload → Splunk integration via Syslog connector and Cisco Security Cloud App
Add a description, image, and links to the siem-integration topic page so that developers can more easily learn about it.
To associate your repository with the siem-integration topic, visit your repo's landing page and select "manage topics."