Full packet capture with flow cutoff, rotation, and compression
☆15Sep 18, 2018Updated 7 years ago
Alternatives and similar repositories for gotm
Users that are interested in gotm are comparing it to the libraries listed below
Sorting:
- provides a Suricata Eve output for Kafka with Suricate Eve plugin☆15Nov 25, 2021Updated 4 years ago
- ☆14Jan 14, 2026Updated last month
- Plugin providing native AF_Packet support for Zeek.☆33Oct 22, 2025Updated 4 months ago
- Dockerized Zeek☆12Mar 9, 2024Updated last year
- Validate if afpacket PACKET_FANOUT_HASH is working properly☆25May 19, 2022Updated 3 years ago
- ☆16Dec 15, 2025Updated 2 months ago
- line based tcp load balancing proxy.☆14Jun 18, 2024Updated last year
- Repository to provide files related to our blog articles.☆16May 26, 2025Updated 9 months ago
- ☆38Nov 20, 2025Updated 3 months ago
- scan-detection policies for bro☆16Jan 16, 2025Updated last year
- Zeek plugin to generate data on per-packet sizes and intervals☆14Apr 21, 2020Updated 5 years ago
- Go implementation of the Community ID flow hashing standard☆21Apr 17, 2025Updated 10 months ago
- High resolution traffic measurement tool for Linux written in Go☆19Jul 28, 2019Updated 6 years ago
- Zeek support for Community ID flow hashing.☆37Jul 11, 2023Updated 2 years ago
- Flow-Indexer indexes flows found in chunked log files from bro,nfdump,syslog, or pcap files☆44May 9, 2024Updated last year
- High performance time ordered PCAP merging utility☆23Jun 20, 2022Updated 3 years ago
- Zeek package for detecting the Eternal* exploits and a set of SMBv1 protocol violations.☆19Aug 21, 2025Updated 6 months ago
- My timewarrior taskwarrior integration scripts☆17Mar 29, 2017Updated 8 years ago
- ☆21Oct 16, 2021Updated 4 years ago
- Expandable Defensive Cyber Operations Platform☆44Sep 28, 2022Updated 3 years ago
- Connect - Stream - Observe - Respond | Morio provides the plumbing for your observability needs☆28Feb 18, 2026Updated last week
- A lens library so small in use you'd hardly notice it's there...☆25Mar 23, 2025Updated 11 months ago
- fast, extensible, versatile event router for Suricata's EVE-JSON format☆57Nov 20, 2025Updated 3 months ago
- Golang Library to interact with your MISP instance☆22Sep 12, 2019Updated 6 years ago
- A Python implementation of the Community ID flow hashing standard☆23Nov 29, 2023Updated 2 years ago
- INACTIVE - http://mzl.la/ghe-archive - Zeek Extreme Performance Tuning☆26Oct 10, 2019Updated 6 years ago
- No elephant flows - flow shunting for Arista switches using EOS API☆27Apr 27, 2021Updated 4 years ago
- Zeek package to generate a SMB client fingerprint☆27May 5, 2020Updated 5 years ago
- (OBSOLETE) Plugins for Bro☆53Sep 13, 2017Updated 8 years ago
- Fetches balances from Coinbase API and returns them as securities☆24Apr 18, 2022Updated 3 years ago
- Suricata Extreme Performance Tuning guide - Mark II☆121Apr 17, 2018Updated 7 years ago
- A Spicy protocol analyzer for WireGuard☆29Aug 11, 2020Updated 5 years ago
- DHCP Fingerprinting☆31Dec 15, 2020Updated 5 years ago
- Robin hood bloom filter (C library)☆37Jul 14, 2024Updated last year
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆37Nov 9, 2022Updated 3 years ago
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆124Nov 19, 2020Updated 5 years ago
- Plugin for Zeek/Bro which provides http2 decoder/analyzer☆30Jun 11, 2024Updated last year
- ☆34May 4, 2020Updated 5 years ago
- A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.☆33Jun 29, 2022Updated 3 years ago