elastic / geneve
☆13Updated this week
Alternatives and similar repositories for geneve:
Users that are interested in geneve are comparing it to the libraries listed below
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated this week
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 3 years ago
- Command line tool used for generating events corpus dynamically given a specific integration☆23Updated 2 months ago
- This repository contains a few examples of actions that can be added to rules within Elastic Security.☆22Updated 2 months ago
- ansible role to setup MISP, Malware Information Sharing Platform & Threat Sharing☆53Updated last week
- Converts Netwitness log parser configuration to Logstash configuration☆20Updated 4 years ago
- An elevated STIX representation of the MITRE ATT&CK Groups knowledge base☆23Updated 2 years ago
- server for indexing and querying passive DNS observations☆46Updated last month
- CyCAT.org API back-end server including crawlers☆29Updated 2 years ago
- Wireshark plugin to display Suricata analysis info☆93Updated 3 years ago
- ☆9Updated last month
- Elastic TIP is a python tool which automates the process of aggregating Threat Intelligence and ingesting the intelligence into a common …☆27Updated 8 months ago
- ☆34Updated 3 months ago
- Threat Intelligence with Elastic - Minemeld integration with Elasticsearch☆19Updated 3 years ago
- Zeek package for tracking long connections to report them before they have completed.☆30Updated 2 months ago
- A Python implementation of the Community ID flow hashing standard☆23Updated last year
- Suricata rule and intel index☆30Updated last month
- A Zeek package that detects Zoom logins and meeting joins☆12Updated 5 years ago
- Build Automated Machine Images for MISP☆28Updated last year
- Elasticsearch/Kibana environment and log data for Sigma workshop☆26Updated 5 years ago
- Core server components for Assemblyline 4 (Alerter, dispatcher, expiry, ingester, scaler, updater, ...)☆20Updated this week
- setup zeek, previously Bro IDS☆18Updated 3 weeks ago
- Zeek support for Community ID flow hashing.☆35Updated last year
- Firepit - STIX Columnar Storage☆16Updated 10 months ago
- Visual Studio Code extension for MITRE ATT&CK☆54Updated 9 months ago
- STIX2 graph visualisation library in JS☆90Updated 2 months ago
- OASIS TC Open Repository: Validator for STIX 2.0 JSON normative requirements and best practices☆51Updated last month
- ☆13Updated 3 years ago
- A few quick recipes for those that do not have much time during the day☆22Updated 5 months ago
- Assemblyline 4 Malware detonation service (Cuckoo)☆17Updated last year