OISF / suricata-trafficid
Application and service identification rules for Suricata
☆18Updated 2 years ago
Alternatives and similar repositories for suricata-trafficid:
Users that are interested in suricata-trafficid are comparing it to the libraries listed below
- Meer (GPLv2) is a dedicated "spooler" for the Suricata & Sagan EVE output formats.☆23Updated 4 years ago
- Suricata rule and intel index☆30Updated 3 weeks ago
- Last download from git://git.carnivore.it/honeytrap.git of Honytrap by Tillmann Werner☆43Updated 3 years ago
- fast, extensible, versatile event router for Suricata's EVE-JSON format☆50Updated 3 weeks ago
- automatic enumeration and maintenance of Suricata monitoring interfaces☆11Updated 5 years ago
- A tools to work on suricata stats.log file.☆28Updated 9 years ago
- CVE Builder script that generates STIX formatted Exploit Target objects☆18Updated 8 years ago
- Plugin for Zeek/Bro which provides http2 decoder/analyzer☆31Updated 10 months ago
- IDS Utility Belt For Automating/Testing Various Things☆30Updated 4 years ago
- How to Zeek Sysmon Logs!☆101Updated 3 years ago
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆31Updated 7 months ago
- Scripts to detect Fast-Flux and DGA using DNS query responses☆43Updated 7 years ago
- YAIDS - Yara-Based IDS - Yara as an Intrusion Detection System / Yet Another Intrusion Detection System - An Intrusion Detection System (…☆23Updated 2 years ago
- A Spicy protocol analyzer for WireGuard☆29Updated 4 years ago
- A tool to generate log messages related to interfaces, neighbor cache (ARP,NDP), IP address, routing, FIB rules, traffic control.☆32Updated 6 months ago
- INACTIVE - http://mzl.la/ghe-archive - Zeek Extreme Performance Tuning☆26Updated 5 years ago
- D4 core software (server and sample sensor client)☆42Updated last year
- ☆35Updated last year
- A Yara Lua output script for Suricata☆19Updated 6 years ago
- Application and service identification rules for Suricata☆29Updated 2 years ago
- Community-based CybergON-powered Suricata rules☆12Updated 2 years ago
- Network timing evaluation used to detect beacons, works with argus flow as the source☆20Updated 8 years ago
- This project is no longer maintained. There's a successor at https://github.com/zeek-packages/zeek-agent-v2☆14Updated 4 years ago
- Quickly generate suricata rules for IOCs☆29Updated 3 years ago
- Pattern recognition for hosts, services, and content☆13Updated 2 years ago
- A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.☆51Updated 6 years ago
- Parse nmap scan data with Perl (official repo)☆36Updated 6 years ago
- Minimalistic DNS logging tool☆43Updated 3 years ago
- Mass deploy and update Suricata IDPS using Ansible IT automation platform☆9Updated 10 years ago
- Prototype system to monitor BGP routes and alert when anomalies are identified☆14Updated 6 years ago