amuehlem / MISP-RPM
RPM packages for MISP
☆35Updated this week
Alternatives and similar repositories for MISP-RPM:
Users that are interested in MISP-RPM are comparing it to the libraries listed below
- misp-cloud - Cloud-ready images of MISP☆72Updated 2 years ago
- ☆34Updated 4 years ago
- A website and framework for testing NIDS detection☆57Updated 3 years ago
- Threat Hunting with ELK Workshop (InfoSecWorld 2017)☆66Updated 7 years ago
- Incident Response Network Tools☆24Updated 3 years ago
- Cerebrate is an open-source platform meant to act as a trusted contact information provider and interconnection orchestrator for other se…☆88Updated 2 weeks ago
- ☆13Updated 3 years ago
- automate your MISP installs☆67Updated 4 years ago
- Remote Desktop Client Fingerprint script for Zeek. Based off of https://github.com/0x4D31/fatt☆39Updated last year
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆35Updated 2 years ago
- A Sigma to Wazuh / OSSEC converter including a generated Windows Sysmon ruleset☆33Updated 4 years ago
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆36Updated 2 years ago
- SOC Workflow App helps Security Analysts and Threat Hunters explore suspicious events, look into raw events arriving at the Elastic Stack…☆94Updated 2 years ago
- This repository hosts files relating to the TF-CSIRT Reference Security Incident Taxonomy Working Group.☆65Updated 3 weeks ago
- Parse wazuh[HIDS] alerts into ECS mapping using Filebeat☆27Updated 4 years ago
- Synapse: a Meta Alert Feeder for TheHive, a Security Incident Response Platform☆71Updated last year
- A collection of tips for using MISP.☆74Updated 4 months ago
- Import specific data sources into the Sigma generic and open signature format.☆78Updated 2 years ago
- YETI (Your Everyday Threat Intelligence) Integration to Elastic Stack☆16Updated 4 years ago
- Utilizing your Threat data from a MISP instance into CarbonBlack Response by exposing the data in the Threat Intelligence Feed.☆19Updated 2 years ago
- CyCAT.org API back-end server including crawlers☆29Updated 2 years ago
- IntelMQ Tutorial and Introductory Documentation☆14Updated 2 years ago
- MISP-STIX-Converter - Python library to handle the conversion between MISP and STIX formats☆53Updated this week
- ☆51Updated 3 years ago
- The aim of this repository is to provide a list of examples of tools, sources and measures available to incident response teams☆58Updated 4 years ago
- Zeek support for Community ID flow hashing.☆35Updated last year
- Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings☆123Updated 3 years ago
- Zeek Extension to Collect Metadata for Profiling of Endpoints and Proxies☆31Updated last year
- A script to create and assign SOP tasks into the cases☆19Updated 4 years ago
- Notes for High Availability MISP in AWS☆19Updated 5 years ago