server for indexing and querying passive DNS observations
☆50Jan 12, 2026Updated 2 months ago
Alternatives and similar repositories for balboa
Users that are interested in balboa are comparing it to the libraries listed below
Sorting:
- fast, extensible, versatile event router for Suricata's EVE-JSON format☆57Nov 20, 2025Updated 4 months ago
- suricata eve.json parser in Go☆15May 16, 2019Updated 6 years ago
- Private Search Set (PSS) is an extension to standard Bloom filter or a standalone hash file to describe and share private set.☆16Jan 10, 2025Updated last year
- Go implementation of the Community ID flow hashing standard☆22Apr 17, 2025Updated 11 months ago
- Cyber threat intelligence crates for Rust☆16Jan 22, 2024Updated 2 years ago
- Suricata JSON schema project☆12Jan 5, 2020Updated 6 years ago
- Passive DNS Common Output Format☆37Aug 30, 2024Updated last year
- revised "peHash: A Novel Approach to Fast Malware Clustering"☆21Jul 13, 2016Updated 9 years ago
- A highly efficient Bloom filter library and command line tool written in Go.☆77Sep 16, 2022Updated 3 years ago
- This script is used for extracting DDE in docx and xlsx☆12Dec 8, 2017Updated 8 years ago
- A Python implementation of our efficient Bloom filter library.☆29Feb 27, 2020Updated 6 years ago
- Enables Zeek to communicate with Tenzir☆11Jul 20, 2023Updated 2 years ago
- High resolution traffic measurement tool for Linux written in Go☆19Jul 28, 2019Updated 6 years ago
- Suricata rules to detect Winnti communication☆16Mar 5, 2018Updated 8 years ago
- A Python implementation of the Community ID flow hashing standard☆23Nov 29, 2023Updated 2 years ago
- Network detector for Winnti malware☆21Mar 6, 2018Updated 8 years ago
- ☆12Jan 28, 2020Updated 6 years ago
- PassiveDNS in Go☆125Feb 16, 2026Updated last month
- command line tool to use the DNSDB Flexible Search API extensions.☆16Aug 5, 2024Updated last year
- YAFRA is a semi-automated framework for analyzing and representing reports about IT Security incidents.☆27Dec 14, 2021Updated 4 years ago
- CLI and Go package for fast, offline ASN lookups☆21Feb 27, 2025Updated last year
- Tools for inspecting YARA bytecode☆21Jul 1, 2020Updated 5 years ago
- eBPF-based EDR for Linux☆18Aug 25, 2024Updated last year
- gonids is a library to parse IDS rules, with a focus primarily on Suricata rule compatibility. There is a discussion forum available that…☆193Jul 18, 2025Updated 8 months ago
- A privacy-aware exchange module to securely and privately share your indicators☆14Aug 23, 2017Updated 8 years ago
- ACT documentation repo☆18May 22, 2024Updated last year
- Repository to provide files related to our blog articles.☆16May 26, 2025Updated 9 months ago
- ☆16Dec 15, 2025Updated 3 months ago
- Zeek package to detect Zerologon☆11Nov 10, 2021Updated 4 years ago
- Suricata Extreme Performance Tuning guide☆213Mar 15, 2018Updated 8 years ago
- Extensions for Zeek's Intelligence Framework.☆11Mar 1, 2022Updated 4 years ago
- Including Haskell, R, Julia,Python and Jupyter Kernels generated by Nix☆13Mar 6, 2023Updated 3 years ago
- ☆42Sep 16, 2022Updated 3 years ago
- Validate if afpacket PACKET_FANOUT_HASH is working properly☆25May 19, 2022Updated 3 years ago
- ☆24Sep 28, 2022Updated 3 years ago
- Zeek package to generate a SMB client fingerprint☆27May 5, 2020Updated 5 years ago
- A Spicy protocol analyzer for WireGuard☆29Aug 11, 2020Updated 5 years ago
- provides a Suricata Eve output for Kafka with Suricate Eve plugin☆15Nov 25, 2021Updated 4 years ago
- simple YARA-based IOC scanner☆176Updated this week