certego / fw1-loggrabber
FW1-Loggrabber is a command-line tool to grab logfiles from remote Checkpoint devices using OPSEC LEA (Log Export API)
☆53Updated 5 years ago
Related projects: ⓘ
- Engine of MineMeld☆141Updated last year
- Contains log parsers for Logstash for many systems and applications. Also contains many methods of augmenting logs.☆55Updated 6 years ago
- CIF v3 -- the fastest way to consume threat intelligence☆181Updated last year
- A tool for analyzing firewall rules☆157Updated 6 years ago
- Threat Feed Aggregation, Made Easy☆166Updated 4 years ago
- Cyber Analytics Platform and Examination System (CAPES) Project Page☆60Updated 5 years ago
- Graylog Processing Pipeline functions to enrich log messages with IoC information from threat intelligence databases☆148Updated 6 months ago
- Suricata Extreme Performance Tuning guide☆202Updated 6 years ago
- ELK configuration files for Forensic Analysts and Incident Handlers (unmaintained)☆179Updated 5 years ago
- Main MineMeld documentation repo☆378Updated 6 years ago
- Collecting & Hunting for IOCs with gusto and style☆116Updated 6 years ago
- Prototypes for MineMeld nodes☆39Updated 2 years ago
- Samples code that uses QRadar API's☆198Updated 4 years ago
- WebUI of MineMeld☆43Updated last year
- Contains Logstash related content including tons of Logstash configurations☆252Updated 3 years ago
- Docker container for MISP☆96Updated 6 years ago
- ☆48Updated 8 years ago
- DEPRECATED - USE v3 (bearded-avenger)☆227Updated 6 years ago
- Ansible playbook for installing MineMeld on Linux☆48Updated 3 years ago
- Bro IDS Dockerfile☆129Updated 5 years ago
- Automated Docker MISP container - Malware Information Sharing Platform and Threat Sharing☆174Updated 3 years ago
- Bro scripts written by CrowdStrike Services☆145Updated 3 years ago
- ☆54Updated this week
- Improvements of/over the original rule2alert☆56Updated 9 years ago
- Splunk App for Linux Auditd☆58Updated 3 years ago
- A utility repo to assist with converting between MISP and STIX formats☆64Updated 3 years ago
- IntelMQ Manager is a graphical interface to manage configurations for IntelMQ framework.☆101Updated 2 months ago
- Cyber Defence Monitoring Course Suite :: Suricata, Arkime (and others in the past)☆99Updated 3 months ago
- PANW Firewall Visualisations using Elastic Stack☆89Updated last year
- A search command for Splunk which will allow you to search Elastic Search and display the results in the Splunk GUI☆67Updated 7 years ago