blacklight / Snort_AIPreprocLinks
A preprocessor module for Snort that uses ML algorithms for pruning, clustering and finding correlation between alerts
☆31Updated 6 years ago
Alternatives and similar repositories for Snort_AIPreproc
Users that are interested in Snort_AIPreproc are comparing it to the libraries listed below
Sorting:
- Network timing evaluation used to detect beacons, works with argus flow as the source☆20Updated 9 years ago
- ☆16Updated 6 years ago
- Zeek scripts that provide an alternative log file logging TLS/SSL traffic☆11Updated 4 years ago
- Repository of creating different example suricata data sets☆34Updated 6 years ago
- • Packet capture (PCAP) file analysis to analyze traffic sent by malicious IP address.☆12Updated 10 years ago
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆31Updated 10 months ago
- A completely automated anomaly detector Zeek network flows files (conn.log).☆81Updated 11 months ago
- Pure python parser for Snort/Suricata rules.☆33Updated last year
- Parse Suricata rules☆13Updated last year
- Pcap-splitter allows you to split a pcap file into subsets of pcap files based on sessions, flows, ip addresses, number of bytes, number …☆65Updated 6 years ago
- Data sets and examples for Jask Labs Blackhat 2017 Handout: Top 10 Machine Learning Cyber Security Use Cases☆30Updated 7 years ago
- Scripts to detect Fast-Flux and DGA using DNS query responses☆43Updated 8 years ago
- This is an open source Snort rules repository☆30Updated 3 years ago
- A vulnerability assessment tool for system models☆13Updated 3 years ago
- This is a malware analysis project which expecte to generate snort rule via malicious network traffic☆28Updated 2 years ago
- A Python library for parsing, manipulating, and generating MAEC content.☆42Updated 4 years ago
- Data and code for malware classification using machine learning (for fun, not production)☆39Updated 5 years ago
- Download all packet captures from http://malware-traffic-analysis.net/☆20Updated 10 years ago
- DGA-generated domain detection using deep learning models☆23Updated 2 years ago
- An anomaly-based intrusion detection system.☆83Updated 2 years ago
- Utility for parsing Bro log files into CSV or JSON format☆41Updated 2 years ago
- YAIDS - Yara-Based IDS - Yara as an Intrusion Detection System / Yet Another Intrusion Detection System - An Intrusion Detection System (…☆24Updated 2 years ago
- Integration between SIEMs and TAXII services☆10Updated 2 years ago
- Malware Machine Learning☆27Updated 7 years ago
- Golang based web service to scan files with yara rules☆26Updated 8 years ago
- Advanced Persistent Threat Detection Using Network Analysis☆22Updated 6 years ago
- DGA Domain Detection using Bigram Frequency Analysis☆54Updated 7 years ago
- A map displaying threat actors from the misp-galaxy☆33Updated 2 years ago
- A dsniff project using bro☆10Updated 9 years ago
- This is the C version of the StratosphereLinuxIPS. It is mainly used for integration with Snort and other IDSs.☆12Updated 8 years ago