SplunkSec / .conf2015
Splunk app to support presentation at .conf2015 on free security tools and Splunk
☆10Updated 9 years ago
Related projects ⓘ
Alternatives and complementary repositories for .conf2015
- Push "BAD" IPs/Networks into QRadar's "Remote Networks", tag them properly, and use them!☆18Updated 11 years ago
- Bro Intel Feed Linter☆26Updated 5 years ago
- ☆55Updated 2 years ago
- Allows for MAC address to vendor mapping in Splunk☆16Updated last year
- Example Splunk Alert Scripts☆20Updated 9 years ago
- Splunk csv to KVStore ES Threat Intel☆10Updated 8 years ago
- Python script that gets IOC from MISP and converts it into BRO intel files.☆13Updated 8 years ago
- scripts to configure the Splunk Universal Forwarder in a locked down state☆40Updated 5 years ago
- Framework that sits on top of Splunk Enterprise Security to do auto-mitigation☆14Updated 9 years ago
- Allows to pull asset and identity data into Splunk app for Enterprise Security from LDAP and other sources☆27Updated 6 years ago
- Broctl plugin for automatically executing 'setcap' on each node after an install☆13Updated 3 years ago
- ☆14Updated 8 years ago
- Bro IDS + ELK Stack to detect and block data exfiltration☆46Updated 6 years ago
- Assorted scripts for Bro☆12Updated 8 years ago
- Just another tool to extract Indicator of compromise (ioc) from files☆28Updated 9 years ago
- ☆23Updated 4 years ago
- Connector for pulling and converting STIX information from TAXII Service Providers into CB Feeds.☆15Updated 2 years ago
- Sysmon Splunk App☆46Updated 6 years ago
- Beholder is a shell script which installs and configures essentials to peer into your network activity.☆19Updated 7 years ago
- Collection of bro scripts☆9Updated 9 years ago
- brocon-15 scripts☆13Updated 7 years ago
- The Bro/Zeek language cheat sheet☆51Updated 11 years ago
- Network Forensics Bro scripts & pcap samples☆62Updated 10 years ago
- A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆67Updated 7 years ago
- Logstash configuration files for analyzing various types of logs☆25Updated 7 years ago
- MineMeld nodes for MISP☆18Updated 10 months ago
- setup zeek, previously Bro IDS☆17Updated 3 weeks ago