activecm / smudge
Passive OS detection based on SYN packets without Transmitting any Data
☆46Updated 2 years ago
Alternatives and similar repositories for smudge:
Users that are interested in smudge are comparing it to the libraries listed below
- Endpoint detection for remote hosts for consumption by RITA and Elasticsearch☆70Updated last year
- Corelight@Home script☆40Updated last year
- Digital Forensic Analysis and Incident Response Playbooks to handle real world security incidents☆39Updated 11 months ago
- Azure function to insert MISP data in to Azure Sentinel☆31Updated 2 years ago
- CSIRT Jump Bag☆26Updated 11 months ago
- Powershell Scripts to work on Crowdstrike Falcon that pull back raw data relevant to forensic investigation☆22Updated 3 months ago
- A tool to modify timestamps in a packet capture to a user selected date☆31Updated 3 years ago
- Sigma detection rules for hunting with the threathunting-keywords project☆55Updated 3 weeks ago
- Network security visualization tool, showcasing live traffic between internal and external hosts in a real-time visualization.☆25Updated last year
- SubCrawl is a modular framework for discovering open directories, identifying unique content through signatures and organizing the data w…☆51Updated 3 months ago
- Extracts fields from zeek logs, compatible with zeek-cut☆21Updated 8 months ago
- Get started using Synapse Open-Source to start a Cortex and perform analysis within your area of expertise.☆41Updated 2 years ago
- DShield Sensor Log Collection with ELK☆22Updated this week
- A MITRE ATT&CK Lookup Tool☆45Updated 11 months ago
- A collection of tips for using MISP.☆74Updated 3 months ago
- A new Cyber Threat Intelligence Capability Maturity Model (CTI-CMM) to empower your team and create lasting value. Inspired by Industry N…☆26Updated last week
- ☆41Updated last year
- ☆46Updated 2 weeks ago
- Track progress and keep notes while working through likethecoins' CTI Self Study Plan☆28Updated 2 years ago
- SkillAegis is a platform to design, run, and monitor exercise scenarios, enhancing skills in applications like MISP and training users in…☆26Updated 2 weeks ago
- Zeek Extension to Collect Metadata for Profiling of Endpoints and Proxies☆29Updated last year
- Automatic detection engineering technical state compliance☆55Updated 8 months ago
- Run Velociraptor on Security Onion☆37Updated 2 years ago
- DNS Dashboard for hunting and identifying beaconing☆15Updated 4 years ago
- PowerShell 'Hero': scripts for DFIR and automation with a PowerShell menu example.☆36Updated last year
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆52Updated 2 years ago
- ☆63Updated last month
- ESXi Cyber Security Incident Response Script☆23Updated 6 months ago
- Logbook for Digital Forensics and Incident Response☆50Updated 8 months ago
- This script provides a Python library with methods to authenticate to various sources of threat intelligence and query IPs for the latest…☆18Updated last month