360netlab / DGA
Suspicious DGA from PDNS and Sandbox.
☆183Updated 2 years ago
Alternatives and similar repositories for DGA:
Users that are interested in DGA are comparing it to the libraries listed below
- A collection of known Domain Generation Algorithms☆66Updated 9 years ago
- The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research th…☆219Updated 7 years ago
- ☆269Updated 6 years ago
- DGA Domains detection☆65Updated 7 years ago
- This repository will hold PCAP IOC data related with known malware samples (owner: Bryant Smith)☆101Updated 3 years ago
- An easy ATT&CK-based Sysmon hunting tool, showing in Blackhat USA 2019 Arsenal☆201Updated 3 years ago
- Extract files from network traffic with Zeek.☆101Updated 5 years ago
- Explore Indicators of Compromise Automatically☆94Updated 5 years ago
- Sample DGA classifier☆124Updated 9 years ago
- Anomaly detection based on DNS traffic analysis☆52Updated 4 years ago
- Pull some Malware samples here for other security researchers/malware analyst's to analyze and play with.☆174Updated 10 months ago
- dns tunnel dectect with CNN☆63Updated 5 years ago
- Malware Sinkhole List in various formats☆103Updated 2 years ago
- Some results of my DGA reversing efforts☆661Updated 2 weeks ago
- Rule sets for Sagan☆102Updated 4 years ago
- Download pcap files from http://www.malware-traffic-analysis.net/☆75Updated 7 years ago
- idstools: Snort and Suricata Rule and Event Utilities in Python (Including a Rule Update Tool)☆281Updated last year
- Passive DNS collection using Zeek☆182Updated last year
- Cyber Threat Intelligence Feeds☆95Updated 8 years ago
- Automatic Yara Rule Generation☆332Updated 9 years ago
- DGA Domain Detection using Bigram Frequency Analysis☆54Updated 7 years ago
- DGA Detection with ML and DL☆47Updated 5 years ago
- ☆307Updated 7 years ago
- Suricata, Snort and Zeek IDS rule and pcap testing system☆474Updated 3 months ago
- This repository contains all public indicators identified by 401trg during the course of our investigations. It also includes relevant ya…☆121Updated 4 years ago
- Django web interface for managing Yara rules☆192Updated 6 years ago
- The Multiplatform Linux Sandbox☆260Updated 3 years ago
- Mapping NSM rules to MITRE ATT&CK☆71Updated 4 years ago
- FANCI is a prototype implementation of a machine learning based classification engine for non-existent domains to detect domain gernation…☆29Updated 6 years ago
- 威胁情报,恶意样本分析,开源Malware代码收集☆339Updated 5 years ago