TcM1911 / stix2
A pure Go library for working with Structured Threat Information Expression (STIX™) version 2.x data
☆23Updated 6 months ago
Alternatives and similar repositories for stix2:
Users that are interested in stix2 are comparing it to the libraries listed below
- Firepit - STIX Columnar Storage☆16Updated 10 months ago
- A Go implementation and parser for Sigma rules.☆86Updated 7 months ago
- A Golang API for TheHive☆13Updated 4 years ago
- APIs for generating STIX 2.1 and TAXII 2.1 messages with Go (Golang)☆53Updated 4 months ago
- Specifications used in the MISP project including MISP core format☆51Updated 3 months ago
- A cyber threat intelligence server based on TAXII 2 and written in Golang☆30Updated 5 years ago
- Yara powered NIDS with high speed packet capture powered by PF_RING☆69Updated 11 months ago
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆31Updated 7 months ago
- gyp: A pure Go YARA parser☆107Updated last year
- fast, extensible, versatile event router for Suricata's EVE-JSON format☆50Updated this week
- Golang library that implements a sigma log rule parser and match engine.☆94Updated 9 months ago
- STIX 2.1 Visualizer, Attack and Activity Thread Graph for Threat Modeling☆32Updated 4 months ago
- A Spicy protocol analyzer for WireGuard☆29Updated 4 years ago
- Zeek support for Community ID flow hashing.☆35Updated last year
- A golang JSON canonicalization scheme library based on RFC 8785☆21Updated last year
- TAXII Server supporting the 2.1 spec.☆19Updated 5 years ago
- Collect autorun records from running system☆61Updated 3 years ago
- A Python library for parsing, manipulating, and generating MAEC content.☆41Updated 4 years ago
- Simple streaming pre-processor and enrichment tool for structured logs.☆11Updated 2 years ago
- Translate STIX 2 Patterning Queries☆31Updated 6 years ago
- OASIS TC Open Repository: The repository cti-stix-slider supports development of a Python application to convert STIX 2.0 content to STIX…☆21Updated last year
- Build a local copy of MITRE ATT&CK and CAPEC. Server mode for easy querying.☆32Updated last week
- OASIS Cyber Threat Intelligence (CTI) TC Open Repository: Convert STIX 1.2 XML to STIX 2.x JSON☆50Updated last year
- An open-source command-line tool for cybersecurity reporting automation and a configuration language for reusable templates. Reporting-as…☆50Updated 3 weeks ago
- Indicator Extractor☆139Updated 6 years ago
- Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)☆100Updated 3 months ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 months ago
- Sighting DB is designed to scale writing and reading a count of attributes, tracking when if was first and last seen☆16Updated last year
- suricata eve.json parser in Go☆15Updated 5 years ago
- OASIS TC Open Repository: Validator for STIX 2.0 JSON normative requirements and best practices☆51Updated last month