Thread Reader
Share this page!
×
Post
Share
Email
Enter URL or ID to Unroll
×
Unroll Thread
You can paste full URL like: https://x.com/threadreaderapp/status/1644127596119195649
or just the ID like: 1644127596119195649
How to get URL link on X (Twitter) App
On the Twitter thread, click on
or
icon on the bottom
Click again on
or
Share Via icon
Click on
Copy Link to Tweet
Paste it above and click "Unroll Thread"!
More info at
Twitter Help
Paul Masek @paulmasek@infosec.exchange
@paul_masek
IT Recruitment Consultant. @BSidesFortWayne Co-founder. GSEC & GIAC Advisory Board. #detectionengineering & #threathunting fan.
Subscribe
Save as PDF
May 13, 2022
•
9 tweets
•
9 min read
#DetectionEngineering
#ThreatHunting
Huge List O' Resources Incoming \/ \/ \/
SIEM Rulesets (all open and free):
@MITREcorp
CAR -
car.mitre.org
@splunk
-
github.com/splunk/securit…
@elastic
-
github.com/elastic/detect…
@sigma_hq
-
github.com/SigmaHQ/sigma/…
👇🧵 Some Free / Some Paid: SIEM Rule Marketplace
@SOC_Prime
:
socprime.com
Great Threat Hunting Guide:
threathunting.net/files/hunt-evi…
Detection engineering guide. Excellent places to look first
@redcanary
:
redcanary.com/threat-detecti…