ExtraHop / code-examples
ExtraHop public code examples
☆33Updated 2 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for code-examples
- Utility to automate generating and uploading STIX files to ExtraHop appliances via the REST API.☆8Updated 4 months ago
- This is a script to import Cisco Talos's IP Blacklist into a Tag (Host Group) within Stealthwatch. This will also optionally create a Cu…☆11Updated last year
- Device profile: Define acceptable amounts of traffic for your devices and see a report of outliers.☆16Updated 4 years ago
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆67Updated last year
- Plugin source code for the InsightConnect SOAR product, developer documentation at https://docs.rapid7.com/insightconnect/getting-started☆67Updated this week
- Collection of walkthroughs on various threat hunting techniques☆75Updated 4 years ago
- Run zeek with zeekctl in docker☆50Updated 2 months ago
- Search a filesystem for indicators of compromise (IoC).☆68Updated 2 months ago
- CrowdStrike's Open Source Policy & Contribution Guide☆39Updated last year
- ☆85Updated this week
- MineMeld nodes for MISP☆18Updated 10 months ago
- Cisco Orbital - Osquery queries by Talos☆124Updated 3 months ago
- Official Palo Alto Networks MineMeld docker☆16Updated 4 years ago
- This script provides a Python library with methods to authenticate to various sources of threat intelligence and query IPs for the latest…☆18Updated 2 years ago
- Attack Range to test detection against nativel serverless cloud services and environments☆35Updated 3 years ago
- Intrusion Detection Honeypots Book Code☆24Updated 4 years ago
- Ansible playbook for installing MineMeld on Linux☆48Updated 3 years ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- ☆53Updated 3 years ago
- Indicators of compromise, YARA rules, and Python scripts to supplement the SANS CTI Summit 2021 talk: "xStart when you're ready".☆14Updated 3 years ago
- Falcon Data Replicator☆30Updated 7 months ago
- Developer enhancements (DX) for FalconPy, the CrowdStrike Python SDK☆37Updated last week
- Cisco eStreamer client☆25Updated 2 years ago
- Parse wazuh[HIDS] alerts into ECS mapping using Filebeat☆27Updated 4 years ago
- A website and framework for testing NIDS detection☆56Updated 3 years ago
- Powershell Scripts to work on Crowdstrike Falcon that pull back raw data relevant to forensic investigation☆22Updated 3 months ago
- Import CrowdStrike Threat Intelligence into your instance of MISP☆42Updated last month
- Threat intelligence and threat detection indicators (IOC, IOA)☆53Updated 3 years ago
- VMware Carbon Black Cloud Python SDK☆42Updated last week