<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
    <title>siem</title>
    <link rel="self" type="application/atom+xml" href="https://links.biapy.com/guest/tags/1270/feed"/>
    <updated>2026-05-12T21:20:07+00:00</updated>
    <id>https://links.biapy.com/guest/tags/1270/feed</id>
            <entry>
            <id>https://links.biapy.com/links/12020</id>
            <title type="text"><![CDATA[MacNoise]]></title>
            <link rel="alternate" href="https://github.com/0xv1n/macnoise" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/12020"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Extensible MacOS system telemetry generator.

MacNoise is an extensible and modular macOS system telemetry generation framework. It generates real system events (network connections, file writes, process spawns, plist mutations, TCC permission probes, and more) so security teams can validate that their EDR, SIEM, and firewall tooling detects what it is supposed to detect.

Related contents:

- [Introducing MacNoise! @ 0xv1n](https://0xv1n.github.io/posts/macnoise/).
- [\#66 @ Erreur 403 :fr:](https://newsletter.erreur403.fr/p/erreur-403-66).]]>
            </summary>
            <updated>2026-03-05T12:11:52+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10908</id>
            <title type="text"><![CDATA[Wildbox]]></title>
            <link rel="alternate" href="https://fabriziosalmi.github.io/wildbox/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10908"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Your Complete Security Operations Platform

Open-source SIEM, CSPM, WAF, and threat intelligence. From git clone to running security scans in just 5 minutes. No vendor lock-in. No complex setup. 

- [Wildbox @ GitHub](https://github.com/fabriziosalmi/wildbox).]]>
            </summary>
            <updated>2025-11-07T14:22:43+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/10327</id>
            <title type="text"><![CDATA[DetectPack Forge]]></title>
            <link rel="alternate" href="https://detect-pack-forge.vercel.app/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/10327"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Turn ideas into detections your SIEM understands. Generate Sigma, KQL, and SPL rules with tests and playbooks in seconds.

 DetectPack Forge turns plain-English behaviors or sample logs into production-ready detection packs — Sigma, KQL (Sentinel), SPL (Splunk) — plus tests and a response playbook, mapped to MITRE ATT&amp;amp;CK, fully powered by Gen AI. 

- [DetectPack Forge @ GitHub](https://github.com/andrewkolagit/DetectPack-Forge).]]>
            </summary>
            <updated>2025-09-22T05:28:45+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/1738</id>
            <title type="text"><![CDATA[Tailpipe]]></title>
            <link rel="alternate" href="https://tailpipe.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/1738"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[select * from logs;

Open source SIEM for instant log insights, powered by DuckDB. Analyze millions of events in seconds, right from your terminal.

- [Tailpipe @ GitHub](https://github.com/turbot/tailpipe).]]>
            </summary>
            <updated>2025-08-28T20:45:47+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/3032</id>
            <title type="text"><![CDATA[Graylog]]></title>
            <link rel="alternate" href="https://graylog.org/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/3032"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[Threat Detection &amp;amp; Incident Response Done Right.
SIEM, Log Management &amp;amp; API Protection.

Graylog is a free and open log management platform.

- [Graylog @ GitHub](https://github.com/Graylog2/graylog2-server).

Related contents:

- [Centralisation des logs : un atout clé pour la sécurité d’un SI @ IT-Connect :fr:](https://www.it-connect.fr/centralisation-des-logs-un-outil-pour-la-securite/).
- [Déployez Graylog sur Debian 12 pour centraliser et analyser vos logs facilement @ IT-Connect :fr:](https://www.it-connect.fr/tuto-graylog-sur-debian-centraliser-et-analyser-logs/).]]>
            </summary>
            <updated>2025-08-29T00:22:17+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4626</id>
            <title type="text"><![CDATA[Sigma]]></title>
            <link rel="alternate" href="https://sigmahq.io/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4626"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[SIEM Detection Format. The shareable detection format for security professionals.

Sigma is a generic, open, and structured detection format that allows security teams to detect relevant log events in a simple and shareable way. 

Detection engineers, threat hunters and all defensive security practitioners collaborate on detection rules. The repository offers more than 3000 detection rules of different type and aims to make reliable detections accessible to all at no cost.

- [Sigma @ GitHub](https://github.com/SigmaHQ/sigma).
- [C&amp;#039;est la fin des antivirus @ Underscore_&amp;#039;s Spotify :fr:](https://open.spotify.com/episode/027iVKcWMdQOmA4iBMduJL).
- [🚨 Découvrez Sigma: l&amp;#039;outil open-source qui révolutionne la détection de menaces ! 🚨 @ Maory SChroder&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/posts/maory-schroder_cybersaezcuritaez-siem-threathunting-activity-7230094685615067136-Y5wi).]]>
            </summary>
            <updated>2025-08-29T04:47:46+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/4790</id>
            <title type="text"><![CDATA[FalconHound]]></title>
            <link rel="alternate" href="https://github.com/FalconForceTeam/FalconHound" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/4790"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[FalconHound is a blue team multi-tool. It allows you to utilize and enhance the power of BloodHound in a more automated fashion. It is designed to be used in conjunction with a SIEM or other log aggregation tool.]]>
            </summary>
            <updated>2025-08-29T05:15:04+00:00</updated>
        </entry>
            <entry>
            <id>https://links.biapy.com/links/6789</id>
            <title type="text"><![CDATA[Wazuh]]></title>
            <link rel="alternate" href="https://wazuh.com/" />
            <link rel="via" type="application/atom+xml" href="https://links.biapy.com/links/6789"/>
            <author>
                <name><![CDATA[Biapy]]></name>
            </author>
            <summary type="text">
                <![CDATA[The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.

- [Wazuh @ GitHub](https://github.com/wazuh/wazuh).

Related contents:

- [Sécuriser son homelab (et les PC des ados) avec Wazuh : une plateforme open source qui a tout d’une grande @ Cyril Beaufrere&amp;#039;s LinkedIn :fr:](https://www.linkedin.com/pulse/s%25C3%25A9curiser-son-homelab-et-les-pc-des-ados-avec-wazuh-une-beaufrere-2inae/).
- [Wazuh - The FREE SIEM You Need to Try! - Installation Guide \[Part 1\] @ Jim&amp;#039;s Garage&amp;#039;s YouTube](https://www.youtube.com/watch?v=R2fQHiOm39A).
- [You Probably Have 1000s of Vulnerabilities... Wazuh Walkthrough @ Jim&amp;#039;s Garage&amp;#039;s YouTube](https://www.youtube.com/watch?v=yKHm2hpnUzM).]]>
            </summary>
            <updated>2025-09-19T12:37:26+00:00</updated>
        </entry>
    </feed>
