brimdata / brimcap
Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)
☆80Updated 6 months ago
Alternatives and similar repositories for brimcap:
Users that are interested in brimcap are comparing it to the libraries listed below
- Open source endpoint agent providing host information to Zeek. [v2]☆80Updated 5 months ago
- PcapMonkey will provide an easy way to analyze pcap using the latest version of Suricata and Zeek.☆153Updated 3 weeks ago
- Suricata Verification Tests - Testing Suricata Output☆106Updated this week
- ☆43Updated 2 years ago
- Suricata rules for network anomaly detection☆159Updated this week
- simple YARA-based IOC scanner☆168Updated 2 months ago
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆70Updated last week
- MITRE Engage™ is a framework for conducting Denial, Deception, and Adversary Engagements.☆63Updated last year
- Suricata rule and intel index☆30Updated 3 weeks ago
- ☆38Updated 5 months ago
- Cisco Orbital - Osquery queries by Talos☆132Updated 7 months ago
- IoT and Operational Technology Honeypot☆105Updated last year
- Anything Sysmon related from the MSTIC R&D team☆152Updated 10 months ago
- Look into EDR events from network☆23Updated last year
- A repository for OSSEC rules and decoders☆54Updated last year
- Collection of various open-source an commercial rulesets for NIDS (especially for Suricata and Snort)☆23Updated last year
- ☆68Updated last month
- Osquery Resources☆60Updated 5 years ago
- A MITRE Caldera plugin☆43Updated 4 months ago
- go-atomicredteam is a Golang application to execute tests as defined in the atomics folder of Red Canary's Atomic Red Team project (https…☆49Updated 2 years ago
- OASIS Cyber Threat Intelligence (CTI) TC: A repository for commonly used STIX objects in order to avoid needless duplication. https://gi…☆92Updated this week
- Arya is a unique tool that produces pseudo-malicious files meant to trigger YARA rules. You can think of it like a reverse YARA.☆247Updated 2 years ago
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆106Updated 2 years ago
- Signature engine for all your logs☆167Updated last year
- Red Canary's eBPF Sensor☆103Updated 9 months ago
- PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Pac…☆95Updated 3 years ago
- Active C2 IoCs☆98Updated 2 years ago
- The Security Analyst ’s Guide to Suricata☆55Updated 10 months ago
- Zeek IDS Dockerfile☆101Updated 2 years ago
- 🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.☆261Updated 2 years ago