Extensions for Zeek's Intelligence Framework.
☆11Mar 1, 2022Updated 4 years ago
Alternatives and similar repositories for intel-extensions
Users that are interested in intel-extensions are comparing it to the libraries listed below
Sorting:
- Enables Zeek to communicate with Tenzir☆11Jul 20, 2023Updated 2 years ago
- Zeek plugin to generate data on per-packet sizes and intervals☆14Apr 21, 2020Updated 5 years ago
- Bro Intel Feed Linter☆26Aug 30, 2019Updated 6 years ago
- Set your logs on fire with Emoji-🔥!☆15Oct 9, 2020Updated 5 years ago
- ☆16Feb 13, 2020Updated 6 years ago
- Bro/Zeek integration with osquery☆93Nov 2, 2020Updated 5 years ago
- Remote Desktop Client Fingerprint script for Zeek. Based off of https://github.com/0x4D31/fatt☆40Jun 20, 2023Updated 2 years ago
- Bro Detection Scripts☆10Mar 9, 2021Updated 4 years ago
- Zeek package to generate a SMB client fingerprint☆27May 5, 2020Updated 5 years ago
- Zeek package to detect Zerologon☆11Nov 10, 2021Updated 4 years ago
- A Bro package to identify connections that are bursting (lots of data and transferring quickly).☆13Oct 15, 2020Updated 5 years ago
- This module detects HTTP requests that are non RFC compliant and used for smuggling☆12Mar 16, 2023Updated 2 years ago
- A Spicy protocol analyzer for WireGuard☆29Aug 11, 2020Updated 5 years ago
- A Zeek plugin to POST logs over HTTP.☆13Feb 10, 2020Updated 6 years ago
- A Zeek package that detects Zoom logins and meeting joins☆12Apr 15, 2020Updated 5 years ago
- ☆16Dec 15, 2025Updated 2 months ago
- line based tcp load balancing proxy.☆14Jun 18, 2024Updated last year
- Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings☆122Jul 12, 2021Updated 4 years ago
- Plugin for Zeek/Bro which provides http2 decoder/analyzer☆30Jun 11, 2024Updated last year
- Including Haskell, R, Julia,Python and Jupyter Kernels generated by Nix☆13Mar 6, 2023Updated 2 years ago
- Add POST body excerpt to Bro's HTTP log☆14Dec 10, 2025Updated 2 months ago
- scan-detection policies for bro☆16Jan 16, 2025Updated last year
- Go implementation of the Community ID flow hashing standard☆21Apr 17, 2025Updated 10 months ago
- Zeek support for Community ID flow hashing.☆36Jul 11, 2023Updated 2 years ago
- ☆18Dec 20, 2024Updated last year
- Prometheus Exporter for Zeek☆20Aug 13, 2025Updated 6 months ago
- Kafka connector to sync Zed lakes to and from Kafka topics☆18Dec 4, 2025Updated 2 months ago
- A package manager for Zeek☆47Jan 8, 2026Updated last month
- Zeek package for detecting the Eternal* exploits and a set of SMBv1 protocol violations.☆19Aug 21, 2025Updated 6 months ago
- ☆21Oct 16, 2021Updated 4 years ago
- Extracting and analyzing URLs from Emails for phishing events☆21Oct 22, 2020Updated 5 years ago
- ☆24Mar 29, 2020Updated 5 years ago
- INACTIVE - http://mzl.la/ghe-archive - Zeek Extreme Performance Tuning☆26Oct 10, 2019Updated 6 years ago
- Run zeek with zeekctl in docker☆63Sep 12, 2024Updated last year
- Learn about a network from a pcap file or reading from an interface☆29Apr 6, 2024Updated last year
- Validate if afpacket PACKET_FANOUT_HASH is working properly☆25May 19, 2022Updated 3 years ago
- Zeek package for tracking long connections to report them before they have completed.☆31Nov 25, 2025Updated 3 months ago
- module for osquery to load Bro logs into tables☆28Apr 28, 2015Updated 10 years ago
- DHCP Fingerprinting☆31Dec 15, 2020Updated 5 years ago