-
Notifications
You must be signed in to change notification settings - Fork 81
Home
V1D1AN edited this page Apr 23, 2022
·
21 revisions
Welcome to the S1EM wiki!
Today, cyber attacks are more numerous and cause damage in companies. Nevertheless, many software products exist to detect cyber threats. The S1EM solution is based on the principle of bringing together the best products in their field, free of charge, and making them quickly interoperable.
S1EM is a SIEM with SIRP and Threat Intel, a full packet capture, all in one.
Inside the solution:
- Cluster Elasticsearch
- Kibana
- Filebeat
- Logstash
- Metricbeat
- Auditbeat
- Heartbeat
- N8n
- Syslog-ng
- Elastalert
- TheHive
- Cortex
- MISP
- OpenCTI
- Arkime
- Suricata
- Zeek
- StoQ
- Mwdb
- Homer
- Traefik
- Clamav
- Watchtower
Note: Cortex v3.1 use ELK connector and the OpenCTI v4 connector