caesar0301 / pcapdpi
Using nDPI/openDPI to detect flow protocols from a PCAP file or live NIC. This program was modified from example in nDPI and I added a periodically cleaning of flow tree to save memory.
☆23Updated 9 years ago
Alternatives and similar repositories for pcapdpi
Users that are interested in pcapdpi are comparing it to the libraries listed below
Sorting:
- IDS Utility Belt For Automating/Testing Various Things☆30Updated 4 years ago
- A tool to generate log messages related to interfaces, neighbor cache (ARP,NDP), IP address, routing, FIB rules, traffic control.☆32Updated 7 months ago
- Prototype system to monitor BGP routes and alert when anomalies are identified☆15Updated 6 years ago
- Plugin providing AF_XDP support for Bro.☆14Updated 4 years ago
- Net2PCAP is a simple network-to-pcap capture file for Linux. Its goal is to be as simple as possible to be used in hostile environments☆39Updated 11 years ago
- Vagrant configuration to setup a Thug honeyclient VM☆20Updated 10 years ago
- Network timing evaluation used to detect beacons, works with argus flow as the source☆20Updated 9 years ago
- Snort/Suricata DAQ module with DPDK patch☆11Updated last year
- IP-ASN-history is a server software to store efficiently the history of BGP announces and quickly lookup IP addresses origins☆45Updated 3 years ago
- Set of scripts to index PCAP files and retrieve packets☆14Updated 9 years ago
- Application and service identification rules for Suricata☆18Updated 2 years ago
- Hakabana monitoring tool using Haka, ElastcSearch and Kibana☆20Updated 10 years ago
- Scripts to detect Fast-Flux and DGA using DNS query responses☆43Updated 7 years ago
- Multiple rules for yara-project for detect compiler/packer/protector☆33Updated 5 years ago
- automatic enumeration and maintenance of Suricata monitoring interfaces☆11Updated 5 years ago
- The Auditd Framework logs and applies security policy to linux auditd data☆15Updated 7 years ago
- The FastIR Server is a Web server to schedule FastIR Collector forensics collect thanks to the FastIR Agent☆12Updated 8 years ago
- ssh key exchange layer for scapy☆13Updated 10 years ago
- Meer (GPLv2) is a dedicated "spooler" for the Suricata & Sagan EVE output formats.☆23Updated 4 years ago
- D4 core software (server and sample sensor client)☆42Updated last year
- Connectors for the Zeek NetControl framework☆19Updated 3 months ago
- BGP Route Leaks Detection☆70Updated 6 years ago
- ☆14Updated last year
- collection of python scripts to capture dns traffic and store it in elasticsearch☆8Updated 3 years ago
- yara rules for crypto detection☆30Updated 11 years ago
- Opensvp is a security tool implementing "attacks" to be able to test the resistance of firewall to protocol level attack.☆48Updated 8 years ago
- A content inspecting SMTP proxy☆17Updated 10 years ago
- Passive DNS V2☆60Updated 11 years ago
- A Docker container for Moloch based on minimal Debian☆26Updated 9 years ago
- Broctl plugin for automatically executing 'setcap' on each node after an install☆13Updated 4 years ago