Zeek-Formatted Threat Intelligence Feeds
☆385Updated this week
Alternatives and similar repositories for Zeek-Intelligence-Feeds
Users that are interested in Zeek-Intelligence-Feeds are comparing it to the libraries listed below
Sorting:
- A set of Zeek scripts to detect ATT&CK techniques.☆620Jun 26, 2024Updated last year
- Standard-Format Threat Intelligence Feeds☆127Updated this week
- Log4j Exploit Detection Logic for Zeek☆19Nov 25, 2025Updated 3 months ago
- 🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.☆269Mar 17, 2023Updated 2 years ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆39Aug 18, 2022Updated 3 years ago
- Automatically created C2 Feeds☆666Updated this week
- Actionable analytics designed to combat threats☆1,006May 25, 2022Updated 3 years ago
- This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple…☆773Jan 28, 2025Updated last year
- Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings☆122Jul 12, 2021Updated 4 years ago
- Your Everyday Threat Intelligence☆1,951Feb 12, 2026Updated 2 weeks ago
- Industrial Control Systems Network Protocol Parsers☆189Sep 4, 2025Updated 5 months ago
- Zeek network security monitor plugin that enables parsing of the Ethernet/IP and Common Industrial Protocol standards☆46May 30, 2024Updated last year
- Watcher - Open Source AI-powered Cyber Threat Intelligence & Hunting Platform. Developed with Django & React JS.☆1,243Feb 18, 2026Updated last week
- Extract and aggregate threat intelligence.☆906Jan 31, 2024Updated 2 years ago
- Incident Response Documentation made easy. Developed by Incident Responders for Incident Responders☆1,059Oct 5, 2023Updated 2 years ago
- Awesome list of keywords and artifacts for Threat Hunting sessions☆638Aug 4, 2025Updated 6 months ago
- Threat Intel IoCs + bits and pieces of dark matter☆434Feb 19, 2026Updated last week
- Real-time, container-based file scanning at enterprise scale☆975Updated this week
- A query aggregator for OSINT based threat hunting☆930Jan 23, 2026Updated last month
- Detect Tactics, Techniques & Combat Threats☆2,263Jan 21, 2026Updated last month
- Threat Pursuit Virtual Machine (VM): A fully customizable, open-sourced Windows-based distribution focused on threat intelligence analysi…☆1,300Jun 1, 2023Updated 2 years ago
- Threat-Intelligence Feeds & Tools & Frameworks☆222Jun 7, 2024Updated last year
- Pythonic way to work with the warning lists defined there: https://github.com/MISP/misp-warninglists☆35Jan 8, 2026Updated last month
- Zeek package to create JSON formatted logs to stream into data analysis systems.☆30Dec 3, 2025Updated 2 months ago
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆2,340Feb 19, 2026Updated last week
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆785Updated this week
- ReversingLabs YARA Rules☆898Nov 3, 2025Updated 3 months ago
- This repository contains analysis scripts, YARA rules, and additional IoCs related to our Telekom Security blog posts.☆118Dec 13, 2023Updated 2 years ago
- Decentralized Cyber Threat Intelligence Kaizen Framework☆27Jan 31, 2022Updated 4 years ago
- A community-driven, open-source project to share detection logic, adversary tradecraft and resources to make detection development more e…☆4,486Jan 12, 2026Updated last month
- Enables Zeek to communicate with Tenzir☆11Jul 20, 2023Updated 2 years ago
- Zeek support for Community ID flow hashing.☆37Jul 11, 2023Updated 2 years ago
- A collection of tips for using MISP.☆76Dec 11, 2024Updated last year
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,173Jul 26, 2023Updated 2 years ago
- Zeek network security monitor plugin that enables parsing of the Tabular Data Stream (TDS) protocol☆25May 30, 2024Updated last year
- Defanged Indicator of Compromise (IOC) Extractor.☆567Aug 28, 2024Updated last year
- IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.☆1,113Feb 14, 2026Updated 2 weeks ago
- IOC from articles, tweets for archives☆318Dec 12, 2023Updated 2 years ago
- Repository of YARA rules made by Trellix ATR Team☆625Mar 18, 2025Updated 11 months ago