DEPRECATED - MozDef: Mozilla Enterprise Defense Platform
Перейти к файлу
Jeff Bryner 68f9911e41 remove persona hook from main html file 2016-12-19 10:13:11 -08:00
.sonar Adding systemd files to MozDef. 2016-08-23 10:28:04 -05:00
alerts Adding updated uwsgi ini config file for mozdefalertplugins init script. 2016-08-10 14:45:07 -05:00
benchmarking
bot
config Adding config and systemdfiles dir with mongod and kibana. 2016-08-23 10:58:18 -05:00
cron Adding defaultTemplate back in 2016-11-04 09:27:00 -05:00
docker update Dockerfile to run detached with supervisor in non daemon mode 2016-11-23 15:08:31 -08:00
docs
examples
initscripts
lib
loginput
logs
meteor remove persona hook from main html file 2016-12-19 10:13:11 -08:00
mq Update GeoLiteCity.dat location in mq plugin 2016-10-19 16:35:46 -05:00
rest
systemdfiles Delete \ 2016-11-29 11:49:40 -06:00
tests
utils
.gitignore
.gitmodules
CONTRIBUTING.md
LICENSE
README.md
analyze_code.sh
requirements.txt add boto3 requirement 2016-11-23 10:44:01 -08:00

README.md

===================================== MozDef: The Mozilla Defense Platform

Why?

The inspiration for MozDef comes from the large arsenal of tools available to attackers. Suites like metasploit, armitage, lair, dradis and others are readily available to help attackers coordinate, share intelligence and finely tune their attacks in real time. Defenders are usually limited to wikis, ticketing systems and manual tracking databases attached to the end of a Security Information Event Management (SIEM) system.

The Mozilla Defense Platform (MozDef) seeks to automate the security incident handling process and facilitate the real-time activities of incident handlers.

Goals:

  • Provide a platform for use by defenders to rapidly discover and respond to security incidents.
  • Automate interfaces to other systems like bunker, banhammer, mig
  • Provide metrics for security events and incidents
  • Facilitate real-time collaboration amongst incident handlers
  • Facilitate repeatable, predictable processes for incident handling
  • Go beyond traditional SIEM systems in automating incident handling, information sharing, workflow, metrics and response automation

Status:

MozDef is in production at Mozilla where we are using it to process over 300 million events per day.

DOCS:

http://mozdef.readthedocs.org/en/latest/