brimdata / brimcap
Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)
☆78Updated 4 months ago
Alternatives and similar repositories for brimcap:
Users that are interested in brimcap are comparing it to the libraries listed below
- Open source endpoint agent providing host information to Zeek. [v2]☆75Updated 4 months ago
- PcapMonkey will provide an easy way to analyze pcap using the latest version of Suricata and Zeek.☆150Updated 11 months ago
- Suricata rules for network anomaly detection☆155Updated this week
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆67Updated last month
- Lupo - Malware IOC Extractor. Debugging module for Malware Analysis Automation☆104Updated 2 years ago
- PacketSifter is a tool/script that is designed to aid analysts in sifting through a packet capture (pcap) to find noteworthy traffic. Pac…☆95Updated 3 years ago
- Suricata Verification Tests - Testing Suricata Output☆104Updated this week
- ☆41Updated 2 years ago
- ☆49Updated this week
- Collection of various open-source an commercial rulesets for NIDS (especially for Suricata and Snort)☆23Updated last year
- Look into EDR events from network☆23Updated 10 months ago
- Active C2 IoCs☆97Updated 2 years ago
- ☆92Updated 3 years ago
- IoT and Operational Technology Honeypot☆105Updated last year
- Anything Sysmon related from the MSTIC R&D team☆149Updated 8 months ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆34Updated 2 years ago
- simple YARA-based IOC scanner☆166Updated last week
- Pathfinder is a plugin for mapping network vulnerabilities, scanned by CALDERA or imported by a supported network scanner, and translatin…☆126Updated 9 months ago
- Yara powered NIDS with high speed packet capture powered by PF_RING☆68Updated 9 months ago
- ☆65Updated this week
- MITRE Engage™ is a framework for conducting Denial, Deception, and Adversary Engagements.☆62Updated 10 months ago
- Linux Evidence Acquisition Framework☆114Updated 4 months ago
- Suricata rule and intel index☆30Updated 2 months ago
- Cisco Orbital - Osquery queries by Talos☆130Updated 5 months ago
- A Cobalt Strike Scanner that retrieves detected Team Server beacons into a JSON object☆165Updated 2 years ago
- ☆44Updated last year
- Visually inspect and force decode YARA and regex matches found in both binary and text data. With Colors.☆112Updated 2 months ago
- Open Dataset of Cobalt Strike Beacon metadata (2018-2022)☆125Updated 2 years ago
- Melody is a transparent internet sensor built for threat intelligence. Supports custom tagging rules and vulnerable application simulatio…☆139Updated last week
- This repository hosts community contributed Kestrel huntflows (.hf) and huntbooks (.ipynb)☆32Updated last year