berthayes / cp-zeekLinks
Analyze Zeek IDS data with ksqlDB running on Confluent Platform via Docker on your laptop. Or spin up an arbitrary number of AWS hosts, each running Confluent Platform and ksqlDB for use in an instructor-led workshop.
☆11Updated 3 years ago
Alternatives and similar repositories for cp-zeek
Users that are interested in cp-zeek are comparing it to the libraries listed below
Sorting:
- ☆19Updated 3 years ago
- Kafka connector for Splunk☆96Updated last week
- Geospatial UDFs for KSQL☆22Updated 4 years ago
- A Python library to help with some common threat hunting data analysis operations☆143Updated 2 years ago
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
- A Workflow for Data Scientists to bring Jupyter Notebook Visualizations to Kibana Dashboards☆45Updated 2 years ago
- ☆15Updated 8 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 weeks ago
- Kibana Milestones Visualization☆90Updated 2 years ago
- Zeek support for Community ID flow hashing.☆36Updated 2 years ago
- SIEM Logstash parsing for more than hundred technologies☆187Updated last week
- Sankey diagram for Kibana visualize.☆31Updated 9 months ago
- Open-source framework to detect outliers in Elasticsearch events☆209Updated 2 years ago
- ☆222Updated last year
- A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆69Updated last month
- This package allows the use of a custom Elastalert Alert which creates alerts with observables in TheHive using TheHive4Py.☆27Updated 4 years ago
- Data validator agains Splunk Common Information Model (CIM)☆76Updated last year
- Dashboards and loader for ROCK NSM dashboards☆49Updated 2 years ago
- OSSEM Common Data Model☆56Updated 3 years ago
- Bro scripts for the ROCK platform. http://rocknsm.io☆34Updated 2 years ago
- Confluent s2s Demo☆10Updated 2 years ago
- ☆38Updated 5 years ago
- Apache Metron☆60Updated 4 years ago
- A Java library for handling TAXII Messages and invoking TAXII Services.☆20Updated 6 years ago
- Collaborative Open Playbook Standard☆158Updated 2 years ago
- RELK -- The Research Elastic Stack (Kafka, Beats, Zookeeper, Logstash, ElasticSearch, Kibana, Spark, & Jupyter -- All in Docker)☆26Updated 5 years ago
- Actionable analytics designed to combat threats based on MITRE's ATT&CK.☆23Updated 6 years ago
- ☆91Updated 2 years ago
- Apache Metron Workshop Lab materials and instructions.☆35Updated 5 years ago
- Web app that provides basic navigation and annotation of ATT&CK matrices☆17Updated 4 years ago