StamusNetworks / suricata-analytics
☆27Updated this week
Related projects ⓘ
Alternatives and complementary repositories for suricata-analytics
- The Security Analyst’s Guide to Suricata☆52Updated 5 months ago
- Cleanup of older MISP events can require some work until now☆24Updated last year
- A collection of tips for using MISP.☆74Updated 7 months ago
- Zeek support for Community ID flow hashing.☆34Updated last year
- Run zeek with zeekctl in docker☆50Updated 2 months ago
- ☆46Updated 2 years ago
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆64Updated last week
- MISP-STIX-Converter - Python library to handle the conversion between MISP and STIX formats☆50Updated this week
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆37Updated 2 years ago
- Zeek Auxiliary Programs☆26Updated 2 months ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 weeks ago
- ☆66Updated 3 months ago
- The FASTEST way to consume threat intel.☆64Updated last year
- Log4j Exploit Detection Logic for Zeek☆19Updated 6 months ago
- The Project can be used to integrate QRadar with MISP Threat Sharing Platform☆39Updated 2 years ago
- Zeek Training Materials/Products☆35Updated last month
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆49Updated 3 weeks ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆50Updated 2 years ago
- Cisco eStreamer client☆25Updated 2 years ago
- A community event for security researchers to share their favorite notebooks☆106Updated 9 months ago
- Learn about a network from a pcap file or reading from an interface☆27Updated 7 months ago
- Import CrowdStrike Threat Intelligence into your instance of MISP☆42Updated last month
- ☆34Updated 3 years ago
- Synthetic Adversarial Log Objects: A Framework for synthentic log generation☆77Updated 10 months ago
- Import specific data sources into the Sigma generic and open signature format.☆77Updated 2 years ago
- Docker image for MISP☆115Updated this week
- Incident Response Network Tools☆23Updated 3 years ago
- The aim of this repository is to provide a list of examples of tools, sources and measures available to incident response teams☆58Updated 4 years ago
- Dockerized Zeek☆10Updated 8 months ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆35Updated 2 years ago