AbGuthrie / goqueryLinks
Provide a shell like interface by utilizing osquery's distributed API
☆81Updated 5 years ago
Alternatives and similar repositories for goquery
Users that are interested in goquery are comparing it to the libraries listed below
Sorting:
- Things to know when DFIR occurs near a vault deployment.☆43Updated 7 years ago
- Competition Infrastructure Management☆86Updated 3 years ago
- How to Zeek Sysmon Logs!☆102Updated 3 years ago
- Extract indicators of compromise from text, including "escaped" ones.☆162Updated 5 years ago
- Simple Docker-based quickstart for osquery, Fleet, and ELK stack☆63Updated 2 years ago
- PhishDetect is a library to help identify phishing pages☆109Updated 2 years ago
- A Go implementation of JARM☆119Updated 3 years ago
- Yara-Endpoint is a tool useful for incident response as well as anti-malware enpoint base on Yara signatures.☆110Updated 7 years ago
- Security Onion Elastic Stack☆46Updated 4 years ago
- Simple Docker Honeypot server emulating small snippets of the Docker HTTP API☆31Updated 4 years ago
- ☆35Updated 4 years ago
- A Spicy protocol analyzer for WireGuard☆29Updated 5 years ago
- Use Markov Chains to obfuscate data as other data☆54Updated 9 years ago
- An extensible honeypot framework☆95Updated 3 years ago
- Paper and Links to Crimeware in the Modern Era☆31Updated 6 years ago
- Threat hunting repo for my independent study on threat hunting with OSQuery☆27Updated 7 years ago
- A lightweight tool to score network traffic and flag anomalies☆123Updated last year
- Threat intelligence and threat detection indicators (IOC, IOA)☆52Updated 4 years ago
- A CVE Heatmap Using CalPlot☆97Updated 4 years ago
- A Passive SSH back-end and scanner.☆104Updated 3 months ago
- threat-intelligence.eu website and repository of information about open standards, documents, methodologies and processes in threat intel…☆49Updated last month
- Serverless honeytoken 🕵🏻♂️☆80Updated 2 years ago
- Yara Ruleset for scanning Linux servers for shells, spamming, phishing and other webserver baddies☆103Updated 4 years ago
- A collection of typical false positive indicators☆55Updated 4 years ago
- Fast Static File Analysis Framework☆104Updated 5 years ago
- Mitre Att&ck Technique Emulation☆82Updated 6 years ago
- References for FIRST CTI 2019 Symposium presentation☆23Updated 6 years ago
- Testing/collecting some container breakouts☆94Updated 6 years ago
- ☆52Updated 7 years ago
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆123Updated 4 years ago