bez0r / BeaconBits
Network timing evaluation used to detect beacons, works with argus flow as the source
☆20Updated 8 years ago
Alternatives and similar repositories for BeaconBits:
Users that are interested in BeaconBits are comparing it to the libraries listed below
- IDS Utility Belt For Automating/Testing Various Things☆30Updated 4 years ago
- Passive DNS V2☆62Updated 10 years ago
- Debian and Red Hat packaging for SIE DNS sensor☆15Updated last year
- A content inspecting SMTP proxy☆17Updated 10 years ago
- Golang based web service to scan files with yara rules☆27Updated 7 years ago
- Scripts to detect Fast-Flux and DGA using DNS query responses☆42Updated 7 years ago
- yara rules for crypto detection☆30Updated 10 years ago
- Help summarize a PCAP file☆33Updated 13 years ago
- Utility for parsing Bro log files into CSV or JSON format☆41Updated 2 years ago
- Download all packet captures from http://malware-traffic-analysis.net/☆20Updated 10 years ago
- automatic enumeration and maintenance of Suricata monitoring interfaces☆11Updated 5 years ago
- Python scripts to parse scans.io ssl data and ingest into elasticsearch for searching☆33Updated 8 years ago
- Multiple rules for yara-project for detect compiler/packer/protector☆33Updated 5 years ago
- Hosted analyzers built for Grapl☆13Updated 2 years ago
- Advanced Persistent Threat Detection Using Network Analysis☆22Updated 5 years ago
- Python bindings to libhtp☆30Updated 4 years ago
- ☆12Updated 7 years ago
- Set of scripts to index PCAP files and retrieve packets☆14Updated 9 years ago
- Logging plugin to bro to send logs to a Kafka broker☆20Updated 7 years ago
- Flow-Indexer indexes flows found in chunked log files from bro,nfdump,syslog, or pcap files☆44Updated 9 months ago
- PGT allows you to generate pcaps using python without touching the network in any way. It is dependent upon scapy.☆28Updated 3 years ago
- python wrapper for the nfdump cli application☆21Updated 3 years ago
- scan-detection policies for bro☆15Updated last month
- Command-line Interface for Binar.ly☆37Updated 8 years ago
- CertWatcher is a new take on monitoring for phishing sites. It is meant to be a set and forget service that will send you a daily report …☆11Updated 4 years ago
- ☆15Updated 10 months ago
- Yara is awesome, but sometimes you need to manipulate the data streams you're scanning in different ways.☆97Updated 10 years ago
- Top DNS Measurement for Bro☆11Updated 4 years ago
- IP-ASN-history is a server software to store efficiently the history of BGP announces and quickly lookup IP addresses origins☆45Updated 2 years ago
- Meer (GPLv2) is a dedicated "spooler" for the Suricata & Sagan EVE output formats.☆23Updated 4 years ago