brimdata / sharkfest-21
Steve McCanne's Sharkfest '21 Talk
☆16Updated 3 years ago
Alternatives and similar repositories for sharkfest-21:
Users that are interested in sharkfest-21 are comparing it to the libraries listed below
- Enables Zeek to communicate with Tenzir☆11Updated last year
- Zeek plugin to generate data on per-packet sizes and intervals☆14Updated 4 years ago
- A Spicy protocol analyzer for WireGuard☆29Updated 4 years ago
- Suricata rule and intel index☆30Updated 2 months ago
- Zeek support for Community ID flow hashing.☆35Updated last year
- Zeek package to generate a SMB client fingerprint☆27Updated 4 years ago
- Remote Desktop Client Fingerprint script for Zeek. Based off of https://github.com/0x4D31/fatt☆39Updated last year
- A Python implementation of the Community ID flow hashing standard☆23Updated last year
- CyCAT.org API back-end server including crawlers☆30Updated 2 years ago
- ☆23Updated 4 years ago
- Generate network maps from packet captures☆31Updated 5 years ago
- Bro script package to create JSON formatted logs to stream into data analysis systems.☆28Updated last year
- Complementary material to presentations at events☆9Updated last year
- CyCAT.org taxonomies☆14Updated 3 years ago
- OSSEC Decoder & Rulesets for Sysmon Events☆15Updated 9 years ago
- Log4j Exploit Detection Logic for Zeek☆19Updated 9 months ago
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆32Updated 5 months ago
- Specifications used in the MISP project including MISP core format☆51Updated last month
- ☆13Updated 2 years ago
- ☆33Updated 3 years ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆34Updated 2 years ago
- Plugin for Zeek/Bro which provides http2 decoder/analyzer☆30Updated 8 months ago
- Zeek package to detect Zerologon☆11Updated 3 years ago
- Actionable analytics designed to combat threats based on MITRE's ATT&CK.☆22Updated 5 years ago
- Searches for Insider Threat Hunting☆30Updated 5 years ago
- Incremental Machine Leaning by example - Detecting suspicious activity in real time with Zeek data streams, River and JA3 hashes☆15Updated 2 years ago
- Bro PCAP Processing and Tagging API☆28Updated 7 years ago
- A Zeek plugin to POST logs over HTTP.☆13Updated 5 years ago
- Extensions for Zeek's Intelligence Framework.☆11Updated 2 years ago
- Integrate Zeek with Alienvault OTX☆25Updated 4 years ago