S1EM is a SIEM with SIRP and Threat Intel, a full packet capture, all in one.
Today, cyber attacks are more numerous and cause damage in companies. Nevertheless, many software products exist to detect cyber threats. The S1EM solution is based on the principle of bringing together the best products in their field, free of charge, and making them quickly interoperable.
Inside the solution:
- Cluster Elasticsearch
- Kibana
- Filebeat
- Logstash
- Metricbeat
- Heartbeat
- Auditbeat
- Syslog-ng
- Elastalert
- TheHive
- Cortex
- MISP
- OpenCTI
- Arkime
- Suricata
- Zeek
- StoQ
- Mwdb
- Heimdall
- Traefik
- Clamav
- Watchtower
Note: Cortex v3.1 use ELK connector and the OpenCTI v4 connector
Guides
- Installation Guide
- Access Guide
- Configuration Guide
- Upgrade guide
- Detection Guide
- Incident Response Guide
- Threat Intel Guide
- Agent Guide
- Architecture Guide
- Troubleshooting Guide
- Screenshot of S1EM
Roadmap
- : Change docker Postgres and Mysql for multi databases
- : Add Spiderfoot
- : Add SOAR shuffle
- : Add OpenCVE
- : Add Codimd
- : Suppress heimdall for Homer
- : The complete documentation
- : Upgrade to elastalert2
- : SSO
- : Interact with Lab-DFIR-SOC
- : Add Capa