carbonblack / cb-integrationLinks
Carbon Black integration Python utility library
☆12Updated 4 years ago
Alternatives and similar repositories for cb-integration
Users that are interested in cb-integration are comparing it to the libraries listed below
Sorting:
- Report Generation from the Carbon Black REST API☆15Updated 3 years ago
- Subscribe to raw VMware Carbon Black EDR event feed and forward to another system, such as Splunk.☆73Updated last year
- Example Splunk Alert Scripts☆20Updated 10 years ago
- Carbon Black API Resources☆93Updated 7 years ago
- Generate STIX XML from OpenIOC XML☆92Updated 6 years ago
- Bro-IDS scripts☆50Updated 9 years ago
- ☆55Updated 3 years ago
- Specifications used in the MISP project including MISP core format☆52Updated 2 months ago
- An OpenTAXII Configuration for MISP☆83Updated 2 years ago
- Bro/Zeek integration with osquery☆94Updated 4 years ago
- A utility repo to assist with converting between MISP and STIX formats☆69Updated 4 years ago
- InvestigationPlaybookSpec☆72Updated 7 years ago
- Carbon Black Feeds☆73Updated 2 years ago
- A framework for receiving and redistributing abuse feeds☆124Updated 5 years ago
- Python IOC Editor☆63Updated 10 years ago
- Multithreaded threat Intelligence gathering built with Python3☆175Updated 7 years ago
- Term concordances for each course in the SANS DFIR curriculum. Used for automated index generation.☆67Updated 5 years ago
- Network Forensics Bro scripts & pcap samples☆63Updated 11 years ago
- Analyze binaries collected in VMware Carbon Black EDR against Yara rules.☆38Updated 2 years ago
- Carbon Black API - Python language bindings☆145Updated last year
- Bro scripts to be shared with the community☆111Updated 12 years ago
- ELK configuration files for Forensic Analysts and Incident Handlers (unmaintained)☆179Updated 6 years ago
- AuditParser☆60Updated 12 years ago
- Splunk csv to KVStore ES Threat Intel☆11Updated 9 years ago
- CrowdStrike Falcon Orchestrator provides automated workflow and response capabilities☆187Updated last year
- stoQ Public Plugins☆71Updated 2 years ago
- Basic Anomaly IDS capabilities with Python and Bro☆105Updated 7 years ago
- Cyber Analytics Platform and Examination System (CAPES) Project Page☆60Updated 6 years ago
- Docker container for MISP☆96Updated 7 years ago
- A package manager for Zeek☆47Updated last week