S1EM
This project is a SIEM with SIRP and Threat Intel, all in one.
Install / Use
/learn @V1D1AN/S1EMREADME

Objectives
Today, cyber attacks are more numerous and cause damage in companies. Nevertheless, many software products exist to detect cyber threats. The S1EM solution is based on the principle of bringing together the best products in their field, free of charge, and making them quickly interoperable.
S1EM is a SIEM with SIRP and Threat Intel, a full packet capture, all in one.
Inside the solution:
- Elasticsearch ( 1 node or Cluster )
- Kibana
- Filebeat
- Logstash
- Metricbeat
- Heartbeat
- Auditbeat
- Fleet
- N8n
- Zircolite
- Velociraptor
- Spiderfoot
- Syslog-ng
- Elastalert
- TheHive
- Cortex ( With Mwdb, Capa, Yara, FileInfo, AssemblyLine )
- MISP
- OpenCTI
- Arkime
- Suricata
- Zeek
- Mwdb
- Traefik
- Codimd
- Watchtower
- Homer

Guides
- :exclamation:Installation Guide
- Access Guide
- Configuration Guide
- Upgrade guide
- Detection Guide
- Incident Response Guide
- Threat Intel Guide
- Agent Guide
- Architecture Guide
- Troubleshooting Guide
- SOAR
- Use EDR Elastic with S1EM
- Use TPOT with S1EM
- Screenshot of S1EM
Try S1EM
For EVTX File, you can try S1EM (Zircolite) with EVTX-ATTACK-SAMPLES. <br /> For Pcap File, you can try S1EM (Suricata/Zeek/Mwdb) with MALWARE-TRAFFIC-ANALYSIS.
Discord
The serveur discord of S1EM : https://discord.gg/uFBzr8fWmC
Roadmap
- [ ] Add OpenCVE
- [ ] The complete documentation
- [ ] SSO
- [ ] Interact with Lab-DFIR-SOC (https://github.com/StevenDias33/Lab-DFIR-SOC)
- [x] Add Capa ( In cortex )
- [x] Add Zircolite
- [x] Add Velociraptor
- [ ] Installation of S1EM with Ansible
- [ ] Integration in Secubian (https://github.com/kidrek/secubian)
- [ ] Integration of T-POT (https://github.com/telekom-security/tpotce)
Related project
https://www.elastic.co <br /> https://github.com/TheHive-Project/Docker-Templates <br /> https://github.com/jasonish/docker-suricata <br /> https://github.com/blacktop/docker-zeek <br /> https://github.com/rskntroot/arkime <br /> https://github.com/coolacid/docker-misp <br /> https://github.com/m0ns7er/ElasticXDR<br /> https://github.com/jertel/elastalert-docker <br /> https://github.com/OpenCTI-Platform/docker <br /> https://github.com/CERT-Polska/mwdb-core <br /> https://github.com/SigmaHQ/sigma <br /> https://github.com/Yara-Rules/rules <br /> https://traefik.io/ <br /> https://docs.linuxserver.io/images/docker-heimdall <br /> https://github.com/cisagov/Malcolm <br /> https://github.com/blueimp/jQuery-File-Upload <br /> https://gchq.github.io/CyberChef/ <br /> https://www.syslog-ng.com/ <br /> https://github.com/bastienwirtz/homer <br /> https://github.com/wagga40/zircolite <br /> https://github.com/weslambert <br /> https://github.com/Velocidex/velociraptor <br />
Special thanks
En français cette fois. <br /> Merci à mes amis et collègues qui m´ont inspiré toutes ces années, qui m´ont aidé, et corrigé des bugs. Je pense à Kidrek, Juju, mlp1515, Wagga40, Xophidia, StevenDias33, Frak113, HiPizzaa,et tous ceux qui n´ont pas forcement de compte github. <br /> Merci à vous :)
Liens github: <br /> https://github.com/kidrek <br /> https://github.com/mlp1515 <br /> https://github.com/frack113 <br /> https://github.com/StevenDias33 <br /> https://github.com/wagga40 <br /> https://github.com/xophidia <br />
Special thanks in english
Thanks to @Mcdave2k1 for your pull requests
Donate
If this project help you reduce time to develop, you can give me a cup of coffee :) <br />
Related Skills
node-connect
335.8kDiagnose OpenClaw node connection and pairing failures for Android, iOS, and macOS companion apps
prose
335.8kOpenProse VM skill pack. Activate on any `prose` command, .prose files, or OpenProse mentions; orchestrates multi-agent workflows.
frontend-design
82.7kCreate distinctive, production-grade frontend interfaces with high design quality. Use this skill when the user asks to build web components, pages, or applications. Generates creative, polished code that avoids generic AI aesthetics.
sonoscli
335.8kControl Sonos speakers (discover/status/play/volume/group).

