corelight / community-id-spec
An open standard for hashing network flows into identifiers, a.k.a "Community IDs".
☆171Updated last month
Related projects ⓘ
Alternatives and complementary repositories for community-id-spec
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆124Updated 4 years ago
- Docker files for building Zeek.☆86Updated last year
- Bro/Zeek integration with osquery☆95Updated 4 years ago
- Suricata Extreme Performance Tuning guide☆204Updated 6 years ago
- 🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.☆258Updated last year
- Plugin providing native AF_Packet support for Zeek.☆33Updated 7 months ago
- Zeek support for Community ID flow hashing.☆34Updated last year
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 weeks ago
- DynamiteNSM is a free Network Security Monitor developed by Dynamite Analytics to enable network visibility and advanced cyber threat det…☆164Updated last year
- A RESTful API frontend for Stenographer☆55Updated last year
- Open source endpoint agent providing host information to Zeek. [v2]☆66Updated last month
- Cisco Orbital - Osquery queries by Talos☆123Updated 2 months ago
- osquery extensions by Trail of Bits☆262Updated last year
- Open-source framework to detect outliers in Elasticsearch events☆205Updated last year
- Tool for managing Zeek deployments.☆53Updated 3 months ago
- Engine of MineMeld☆141Updated last year
- The default package source of the Zeek Package Manager. Wrote a package? See the README for how to get it included.☆130Updated this week
- Wireshark plugin to display Suricata analysis info☆91Updated 3 years ago
- TAXII client implementation from EclecticIQ☆98Updated 3 years ago
- a network packet capture compiler☆194Updated 2 years ago
- Cyber Defence Monitoring Course Suite :: Suricata, Arkime (and others in the past)☆100Updated 5 months ago
- Passive Real-time Asset Detection System☆232Updated 5 months ago
- A Linux Auditd rule set mapped to MITRE's Attack Framework☆89Updated last year
- Apache Metron☆59Updated 4 years ago
- Main Build directory☆177Updated 5 years ago
- Automated Docker MISP container - Malware Information Sharing Platform and Threat Sharing☆175Updated 3 years ago
- Mapping NSM rules to MITRE ATT&CK☆68Updated 4 years ago
- Suricata Extreme Performance Tuning guide - Mark II☆113Updated 6 years ago
- CIF v3 -- the fastest way to consume threat intelligence☆184Updated last year