SuperCowPowers / zat
Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark
☆435Updated last year
Alternatives and similar repositories for zat:
Users that are interested in zat are comparing it to the libraries listed below
- An analytical framework for network traffic and behavioral analytics☆449Updated 2 years ago
- Threat Report ATT&CK™ Mapping (TRAM) is a tool to aid analyst in mapping finished reports to ATT&CK.☆348Updated 3 years ago
- Suricata, Snort and Zeek IDS rule and pcap testing system☆472Updated 2 months ago
- A set of Zeek scripts to detect ATT&CK techniques.☆578Updated 8 months ago
- Python Script to access ATT&CK content available in STIX via a public TAXII server☆561Updated 2 months ago
- Tool to extract indicators of compromise from security reports in PDF format☆433Updated 2 years ago
- MISP Docker (XME edition)☆283Updated last year
- Python library using the MISP Rest API☆453Updated 2 weeks ago
- A Python package to interact with the Mitre ATT&CK Framework☆475Updated last year
- Cyber Analytics Repository☆923Updated 11 months ago
- OASIS TC Open Repository: Python APIs for STIX 2☆377Updated this week
- idstools: Snort and Suricata Rule and Event Utilities in Python (Including a Rule Update Tool)☆282Updated last year
- Documentation of TheHive☆395Updated last year
- CASCADE Server☆266Updated 2 years ago
- Data from a BRAWL Automated Adversary Emulation Exercise☆204Updated 4 years ago
- ☆1,066Updated 5 years ago
- Modules for expansion services, enrichment, import and export in MISP and other tools.☆353Updated this week
- Scirius is a web application for Suricata ruleset management and threat hunting.☆646Updated 3 months ago
- The tool for updating your Suricata rules.☆266Updated 3 months ago
- A threat hunting / data analysis environment based on Python, Pandas, PySpark and Jupyter Notebook.☆241Updated 3 years ago
- Documentation of Cortex☆173Updated last year
- PCAP Samples for Different Post Exploitation Techniques☆354Updated 3 years ago
- Deception based detection techniques mapped to the MITRE’s ATT&CK framework☆289Updated 7 years ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆788Updated last year
- Actionable analytics designed to combat threats☆982Updated 2 years ago
- The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).☆542Updated last year
- Extract and aggregate threat intelligence.☆851Updated last year
- A datasource assessment on an event level to show potential coverage or the MITRE ATT&CK framework☆350Updated 4 years ago
- Defanged Indicator of Compromise (IOC) Extractor.☆521Updated 6 months ago
- A Splunk app mapped to MITRE ATT&CK to guide your threat hunts☆1,146Updated last year