COSSAS / dgad
DGA Detective - Hunt domains generated by Domain Generation Algorithms to identify malware traffic
☆38Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for dgad
- MITRE Engage™ is a framework for conducting Denial, Deception, and Adversary Engagements.☆60Updated 7 months ago
- A MITRE Caldera plugin☆38Updated this week
- This repository hosts community contributed Kestrel analytics☆15Updated 5 months ago
- This repository hosts community contributed Kestrel huntflows (.hf) and huntbooks (.ipynb)☆31Updated 10 months ago
- CyCAT.org API back-end server including crawlers☆30Updated last year
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆64Updated last week
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆35Updated 2 years ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆50Updated 2 years ago
- Threat Detection Rules (Snort/Sigma/Yara)☆13Updated 9 months ago
- ☆41Updated last year
- pyJARM is a library for doing JARM fingerprinting using python☆50Updated 3 years ago
- This repository contains OpenIOC rules to aid in hunting for indicators of compromise and TTPs focused on Advanced Persistent Threat grou…☆20Updated last year
- Tool to read EVTX files including SYSMON and convert to JSON, MISP Objects and Graph stream☆11Updated 4 years ago
- ☆41Updated 7 months ago
- This script scans the files extracted by Zeek with YARA rules located on the rules folder on a Linux based Zeek sensor, if there is a mat…☆60Updated 11 months ago
- Automated detection rule analysis utility☆29Updated 2 years ago
- Threat Mapping Catalogue☆17Updated 3 years ago
- An elevated STIX representation of the MITRE ATT&CK Groups knowledge base☆23Updated 2 years ago
- ☆46Updated 2 years ago
- Lightweight Python-Based Malware Analysis Pipeline☆29Updated last month
- Sightings Ecosystem gives cyber defenders visibility into what adversaries actually do in the wild. With your help, we are tracking MITRE…☆34Updated 7 months ago
- Repository of all the sites related to infosec IP/Domain/Hash/SSL/etc OSINT and eventually will include more.☆65Updated 6 months ago
- This repository includes a mapping table and a reference process that allows converting between STIX 2.1 Course of Action objects that ma…☆15Updated 2 years ago
- ☆38Updated 10 months ago
- A CALDERA plugin for ATT&CK Evaluations Round 1☆33Updated last year
- Graph Representation of MITRE ATT&CK's CTI data☆48Updated 5 years ago
- ☆24Updated last year
- Import Mitre Att&ck into Neo4j database☆33Updated last year