Converts Netwitness log parser configuration to Logstash configuration
☆20Sep 10, 2020Updated 5 years ago
Alternatives and similar repositories for rsa2elk
Users that are interested in rsa2elk are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Parse Suricata rules☆14Aug 1, 2023Updated 3 years ago
- This repository contains a few examples of actions that can be added to rules within Elastic Security.☆24Feb 6, 2025Updated last year
- Parse wazuh[HIDS] alerts into ECS mapping using Filebeat☆28Jul 21, 2020Updated 6 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆33Jul 21, 2026Updated last month
- Synapse: a Meta Alert Feeder for TheHive, a Security Incident Response Platform☆73Jul 28, 2023Updated 3 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Elastic TIP is a python tool which automates the process of aggregating Threat Intelligence and ingesting the intelligence into a common …☆27Jul 30, 2024Updated 2 years ago
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Mar 9, 2022Updated 4 years ago
- SIEM Logstash parsing for more than hundred technologies☆198Sep 1, 2026Updated last week
- Listing releases of the Elastic stack with new features and references☆19Aug 5, 2026Updated last month
- ☆12Apr 22, 2022Updated 4 years ago
- MasterParser is a simple, all-in-one, digital forensics artifact parser☆24Jul 9, 2021Updated 5 years ago
- YETI (Your Everyday Threat Intelligence) Integration to Elastic Stack☆16Jan 6, 2021Updated 5 years ago
- Super light, super fast, unlimited search idea☆27Aug 3, 2025Updated last year
- Kibana Milestones Visualization☆89Jul 19, 2023Updated 3 years ago
- GPUs on demand by Runpod - Special Offer Available • AdRun AI, ML, and HPC workloads on powerful cloud GPUs—without limits or wasted spend. Deploy GPUs in under a minute and pay by the second.
- ML Toolkit & Showcase application documents☆14May 23, 2016Updated 10 years ago
- ☆12Jul 12, 2026Updated last month
- Flexmonster Pivot Table & Charts plugin for Kibana☆64Jun 20, 2023Updated 3 years ago
- A selection of Canvas workpad examples☆86Aug 19, 2021Updated 5 years ago
- Jupyter Notebooks for Digital Forensics & Incident Response☆10Nov 23, 2021Updated 4 years ago
- WebUI of MineMeld☆42Mar 16, 2023Updated 3 years ago
- The "DFUR" Splunk application and data that was presented at the 2020 SANS DFIR Summit.☆13Sep 9, 2020Updated 5 years ago
- ansible role to setup MISP, Malware Information Sharing Platform & Threat Sharing☆59Updated this week
- Ingest Nessus files into Elasticsearch using PowerShell!☆21Apr 26, 2024Updated 2 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Matt's DFIR blog☆14Jun 23, 2026Updated 2 months ago
- Digital Forensics and Incident Response notes and Autopsy tool walkthrough☆11Feb 3, 2022Updated 4 years ago
- Ansible playbook for installing MineMeld on Linux☆47Mar 18, 2021Updated 5 years ago
- Threat Intelligence with Elastic - Minemeld integration with Elasticsearch☆19May 11, 2021Updated 5 years ago
- The "Let's-defend-solution" directory contains the answers to all paths of the Let's Defend platform that were saved by the creator 8 mon…☆13Aug 11, 2026Updated 3 weeks ago
- Documentation for DFIR ORC, artefact collection tool dedicated to Microsoft Windows☆12May 4, 2026Updated 4 months ago
- Updated Malware Crawler to populate repositories☆10Jul 6, 2015Updated 11 years ago
- CyberSecurity Resources (Threat Intelligence, Malware Analysis, Pentesting, DFIR, etc)☆11Nov 30, 2023Updated 2 years ago
- Import specific data sources into the Sigma generic and open signature format.☆78May 6, 2022Updated 4 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Technical add-on for Splunk related to TheHive/Cortex from TheHive project☆55Aug 19, 2026Updated 2 weeks ago
- Base Vagrant file for Hortonworks Data Platform (HDP) instances☆10Feb 2, 2019Updated 7 years ago
- An Apache Spark app for making data movement between Apache Hive and Apache Phoenix/HBase☆14Mar 23, 2016Updated 10 years ago
- Active Response plugin. Osquery to execute wazuh/ossec active response plugins. You can write your own plugins, easy to plug☆12Jun 20, 2020Updated 6 years ago
- Placeholder for my detection repo and misc detection engineering content☆44Oct 20, 2023Updated 2 years ago
- An alfred workflow to easily search the elastic documentation☆15Oct 12, 2021Updated 4 years ago
- An Ansible role for automated installation of tools from a Tool Shed into Galaxy.☆14Jun 17, 2024Updated 2 years ago