SkillAgentSearch skills...

S1EM

This project is a SIEM with SIRP and Threat Intel, all in one.

Install / Use

/learn @V1D1AN/S1EM

README

20210518_v1d1an_bg1--white

<div> <p align="center"> <a href="https://discord.gg/uFBzr8fWmC" target"_blank"><img src="https://img.shields.io/badge/chat-on%20discord-7289da.svg?sanitize=true" alt="Discord"></a> <img src="https://img.shields.io/badge/Platform-Lin-green"> <img src="https://img.shields.io/badge/Architecture-64bit-red"> <a href="https://www.paypal.com/donate/?business=DUEQFS9Z2E9XW&no_recurring=0&item_name=If+this+project+help+you+reduce+time+to+develop%2C+you+can+give+me+a+cup+of+coffee+%3A%29&currency_code=EUR" target"_blank"><img src="https://img.shields.io/badge/Donate-PayPal-green.svg"> </p> </div>

Objectives

Today, cyber attacks are more numerous and cause damage in companies. Nevertheless, many software products exist to detect cyber threats. The S1EM solution is based on the principle of bringing together the best products in their field, free of charge, and making them quickly interoperable.

S1EM is a SIEM with SIRP and Threat Intel, a full packet capture, all in one.

Inside the solution:

  • Elasticsearch ( 1 node or Cluster )
  • Kibana
  • Filebeat
  • Logstash
  • Metricbeat
  • Heartbeat
  • Auditbeat
  • Fleet
  • N8n
  • Zircolite
  • Velociraptor
  • Spiderfoot
  • Syslog-ng
  • Elastalert
  • TheHive
  • Cortex ( With Mwdb, Capa, Yara, FileInfo, AssemblyLine )
  • MISP
  • OpenCTI
  • Arkime
  • Suricata
  • Zeek
  • Mwdb
  • Traefik
  • Codimd
  • Watchtower
  • Homer

S1EM

Guides

Try S1EM

For EVTX File, you can try S1EM (Zircolite) with EVTX-ATTACK-SAMPLES. <br /> For Pcap File, you can try S1EM (Suricata/Zeek/Mwdb) with MALWARE-TRAFFIC-ANALYSIS.

Discord

The serveur discord of S1EM : https://discord.gg/uFBzr8fWmC

Roadmap

  • [ ] Add OpenCVE
  • [ ] The complete documentation
  • [ ] SSO
  • [ ] Interact with Lab-DFIR-SOC (https://github.com/StevenDias33/Lab-DFIR-SOC)
  • [x] Add Capa ( In cortex )
  • [x] Add Zircolite
  • [x] Add Velociraptor
  • [ ] Installation of S1EM with Ansible
  • [ ] Integration in Secubian (https://github.com/kidrek/secubian)
  • [ ] Integration of T-POT (https://github.com/telekom-security/tpotce)

Related project

https://www.elastic.co <br /> https://github.com/TheHive-Project/Docker-Templates <br /> https://github.com/jasonish/docker-suricata <br /> https://github.com/blacktop/docker-zeek <br /> https://github.com/rskntroot/arkime <br /> https://github.com/coolacid/docker-misp <br /> https://github.com/m0ns7er/ElasticXDR<br /> https://github.com/jertel/elastalert-docker <br /> https://github.com/OpenCTI-Platform/docker <br /> https://github.com/CERT-Polska/mwdb-core <br /> https://github.com/SigmaHQ/sigma <br /> https://github.com/Yara-Rules/rules <br /> https://traefik.io/ <br /> https://docs.linuxserver.io/images/docker-heimdall <br /> https://github.com/cisagov/Malcolm <br /> https://github.com/blueimp/jQuery-File-Upload <br /> https://gchq.github.io/CyberChef/ <br /> https://www.syslog-ng.com/ <br /> https://github.com/bastienwirtz/homer <br /> https://github.com/wagga40/zircolite <br /> https://github.com/weslambert <br /> https://github.com/Velocidex/velociraptor <br />

Special thanks

En français cette fois. <br /> Merci à mes amis et collègues qui m´ont inspiré toutes ces années, qui m´ont aidé, et corrigé des bugs. Je pense à Kidrek, Juju, mlp1515, Wagga40, Xophidia, StevenDias33, Frak113, HiPizzaa,et tous ceux qui n´ont pas forcement de compte github. <br /> Merci à vous :)

Liens github: <br /> https://github.com/kidrek <br /> https://github.com/mlp1515 <br /> https://github.com/frack113 <br /> https://github.com/StevenDias33 <br /> https://github.com/wagga40 <br /> https://github.com/xophidia <br />

Special thanks in english

Thanks to @Mcdave2k1 for your pull requests

Donate

If this project help you reduce time to develop, you can give me a cup of coffee :) <br />

paypal

Related Skills

View on GitHub
GitHub Stars461
CategoryDevelopment
Updated21d ago
Forks89

Languages

Shell

Security Score

100/100

Audited on Mar 4, 2026

No findings