DanielSchwartz1 / SplunkForPCAPLinks
The PCAP Analyzer for Splunk includes useful Dashboards to analyze network packet capture files from Wireshark or Network Monitor (.pcap) and network streaming data (Splunk App for Stream). The App includes Dashboards which will show you: - The Top Talker IP's, Protocols, VLANs, Conversations - Detailed overview about IP Conversations, Packet L…
☆44Updated last year
Alternatives and similar repositories for SplunkForPCAP
Users that are interested in SplunkForPCAP are comparing it to the libraries listed below
Sorting:
- A website and framework for testing NIDS detection☆57Updated 4 years ago
- Bro IDS + ELK Stack to detect and block data exfiltration☆46Updated 7 years ago
- MineMeld nodes for MISP☆19Updated last year
- Threat Hunting with ELK Workshop (InfoSecWorld 2017)☆65Updated 8 years ago
- Security Onion Elastic Stack☆46Updated 4 years ago
- Download a list of suspected malicious IPs and Domains. Create a QRadar Reference Set. Search Your Environment For Malicious IPs☆69Updated 4 years ago
- ☆35Updated 4 years ago
- Bluewall is a firewall framework designed for offensive and defensive cyber professionals.☆106Updated 6 years ago
- Sysmon Splunk App☆47Updated 7 years ago
- Connect your mail client/infrastructure to MISP in order to create events based on the information contained within mails.☆69Updated 2 years ago
- WebUI of MineMeld☆43Updated 2 years ago
- ☆13Updated 6 years ago
- Presentation Slides and Video links☆32Updated 4 years ago
- SOC Workflow App helps Security Analysts and Threat Hunters explore suspicious events, look into raw events arriving at the Elastic Stack…☆94Updated 3 years ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆38Updated 3 years ago
- A tool to assess data quality, built on top of the awesome OSSEM.☆79Updated 3 years ago
- Expert Investigation Guides☆51Updated 4 years ago
- A collection of notebooks built for defensive and offensive operations.☆77Updated 5 years ago
- Splunk App to assist Sysmon Threat Hunting☆38Updated 8 years ago
- Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings☆122Updated 4 years ago
- Tools for the Computer Incident Response Team☆148Updated 8 years ago
- automate your MISP installs☆68Updated 5 years ago
- Threat Intelligence with Elastic - Minemeld integration with Elasticsearch☆19Updated 4 years ago
- CIFv3 DeploymentKit☆64Updated 5 years ago
- Scripts to inject demo data and network traffic into an existing Alienvault/OSSIM installation☆21Updated 8 years ago
- Integrating Sysinternals Autoruns’ logs into Security Onion☆31Updated last year
- Exports MISP events to STIX and ingest into McAfee ESM☆15Updated 5 years ago
- ☆21Updated 5 years ago
- This program exports MITRE ATT&CK framework in ELK dashboard☆80Updated 3 years ago
- Log Entry to Sigma Rule Converter☆108Updated 3 years ago