blacklight / Snort_AIPreproc
A preprocessor module for Snort that uses ML algorithms for pruning, clustering and finding correlation between alerts
☆31Updated 5 years ago
Alternatives and similar repositories for Snort_AIPreproc:
Users that are interested in Snort_AIPreproc are comparing it to the libraries listed below
- A completely automated anomaly detector Zeek network flows files (conn.log).☆75Updated 5 months ago
- Zeek scripts that provide an alternative log file logging TLS/SSL traffic☆10Updated 3 years ago
- Network timing evaluation used to detect beacons, works with argus flow as the source☆19Updated 8 years ago
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆31Updated 4 months ago
- Repository of creating different example suricata data sets☆31Updated 6 years ago
- This is a malware analysis project which expecte to generate snort rule via malicious network traffic☆28Updated last year
- ☆16Updated 5 years ago
- Pcap-splitter allows you to split a pcap file into subsets of pcap files based on sessions, flows, ip addresses, number of bytes, number …☆66Updated 5 years ago
- calculate flow information from PCAP and extract tcp streams☆69Updated 6 months ago
- • Packet capture (PCAP) file analysis to analyze traffic sent by malicious IP address.☆12Updated 10 years ago
- The stratosphere testing framework is mean to help in the researching and verification of the behavioral models used by the Stratoshpere …☆50Updated 6 years ago
- Data sets and examples for Jask Labs Blackhat 2017 Handout: Top 10 Machine Learning Cyber Security Use Cases☆31Updated 7 years ago
- User anomaly detector based on logs generated by Osquery framework and machine learning to process those logs.☆33Updated 7 years ago
- System for network traffic analysis and anomaly detection.☆89Updated 3 months ago
- Use PyShark and scapy to read fields from a pcap file and populate a CSV☆55Updated 4 years ago
- Plugin providing AF_XDP support for Bro.☆14Updated 3 years ago
- Detect cryptocurrency mining traffic with Zeek.☆46Updated 3 years ago
- suricata eve.json parser in Go☆14Updated 5 years ago
- zeek-scripts☆43Updated 6 years ago
- A Zeek script to generate features based on timing, volume and metadata for traffic classification.☆54Updated 4 years ago
- Mapping NSM rules to MITRE ATT&CK☆68Updated 4 years ago
- This repository will hold PCAP IOC data related with known malware samples (owner: Bryant Smith)☆100Updated 3 years ago
- Ender of Fast-Flux malicious domains.☆26Updated 10 years ago
- Pure python parser for Snort/Suricata rules.☆29Updated 10 months ago
- Extract files from network traffic with Zeek.☆100Updated 4 years ago
- Meer (GPLv2) is a dedicated "spooler" for the Suricata & Sagan EVE output formats.☆23Updated 3 years ago
- Apache Metron☆59Updated 4 years ago
- A Python library for parsing, manipulating, and generating MAEC content.☆41Updated 4 years ago
- Collection of Snort 2/3 rules.☆34Updated 6 years ago
- ICS Cybersecurity PCAP respository☆51Updated 6 years ago