An open standard for hashing network flows into identifiers, a.k.a "Community IDs".
☆194Sep 23, 2024Updated last year
Alternatives and similar repositories for community-id-spec
Users that are interested in community-id-spec are comparing it to the libraries listed below
Sorting:
- Zeek support for Community ID flow hashing.☆36Jul 11, 2023Updated 2 years ago
- Dockerized Zeek☆12Mar 9, 2024Updated last year
- Go implementation of the Community ID flow hashing standard☆21Apr 17, 2025Updated 10 months ago
- A Python implementation of the Community ID flow hashing standard☆23Nov 29, 2023Updated 2 years ago
- Bro analyzer that detects Google's QUIC protocol☆10Mar 2, 2021Updated 5 years ago
- Enables Zeek to communicate with Tenzir☆11Jul 20, 2023Updated 2 years ago
- A simple way of detecting multithreaded exfiltration in Zeek.☆15May 1, 2025Updated 10 months ago
- Zeek package for tracking long connections to report them before they have completed.☆31Nov 25, 2025Updated 3 months ago
- Firepit - STIX Columnar Storage☆18Jun 5, 2024Updated last year
- Generate network maps from packet captures☆30Sep 15, 2019Updated 6 years ago
- Private Search Set (PSS) is an extension to standard Bloom filter or a standalone hash file to describe and share private set.☆16Jan 10, 2025Updated last year
- Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings☆122Jul 12, 2021Updated 4 years ago
- The default package source of the Zeek Package Manager. Wrote a package? See the README for how to get it included.☆143Updated this week
- How to Zeek Sysmon Logs!☆103Feb 12, 2022Updated 4 years ago
- A set of Zeek scripts to detect ATT&CK techniques.☆620Jun 26, 2024Updated last year
- A Bro package to identify connections that are bursting (lots of data and transferring quickly).☆13Oct 15, 2020Updated 5 years ago
- 🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.☆269Mar 17, 2023Updated 2 years ago
- A RESTful API frontend for Stenographer☆54Dec 7, 2022Updated 3 years ago
- Remote Desktop Client Fingerprint script for Zeek. Based off of https://github.com/0x4D31/fatt☆40Jun 20, 2023Updated 2 years ago
- Suricata rule and intel index☆33Jan 13, 2026Updated last month
- Repository to provide files related to our blog articles.☆16May 26, 2025Updated 9 months ago
- Real-time, container-based file scanning at enterprise scale☆975Feb 25, 2026Updated last week
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆33Nov 3, 2025Updated 4 months ago
- Cyber Analytics Repository☆984May 16, 2025Updated 9 months ago
- scan-detection policies for bro☆16Jan 16, 2025Updated last year
- Full packet capture with flow cutoff, rotation, and compression☆15Sep 18, 2018Updated 7 years ago
- Sighting DB is designed to scale writing and reading a count of attributes, tracking when if was first and last seen☆17Apr 11, 2024Updated last year
- Add POST body excerpt to Bro's HTTP log☆14Dec 10, 2025Updated 2 months ago
- C++ parser generator for dissecting protocols & files.☆288Feb 25, 2026Updated last week
- GQUIC Protocol Analyzer for Zeek (Bro) Network Security Monitor☆80Sep 13, 2023Updated 2 years ago
- Scirius is a web application for Suricata ruleset management and threat hunting.☆673Dec 23, 2025Updated 2 months ago
- Zeek Training Materials/Products☆41Feb 2, 2026Updated last month
- Zeek package to generate a SMB client fingerprint☆27May 5, 2020Updated 5 years ago
- Validate if afpacket PACKET_FANOUT_HASH is working properly☆25May 19, 2022Updated 3 years ago
- DynamiteNSM is a free Network Security Monitor developed by Dynamite Analytics to enable network visibility and advanced cyber threat det…☆172May 23, 2023Updated 2 years ago
- Plugin providing native AF_Packet support for Zeek.☆33Oct 22, 2025Updated 4 months ago
- fast, extensible, versatile event router for Suricata's EVE-JSON format☆57Nov 20, 2025Updated 3 months ago
- Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search☆484Feb 19, 2026Updated 2 weeks ago
- ** README ** This repo has MOVED to https://github.com/quadrantsec/sagan☆229Feb 9, 2021Updated 5 years ago