gdestuynder / audisp-cef
CEF plugin for audisp (Linux Audit)
☆23Updated 8 years ago
Alternatives and similar repositories for audisp-cef:
Users that are interested in audisp-cef are comparing it to the libraries listed below
- ☆42Updated 4 years ago
- Broctl plugin for automatically executing 'setcap' on each node after an install☆13Updated 4 years ago
- ☆24Updated 5 years ago
- Meer (GPLv2) is a dedicated "spooler" for the Suricata & Sagan EVE output formats.☆23Updated 4 years ago
- CVE Builder script that generates STIX formatted Exploit Target objects☆18Updated 8 years ago
- Vagrant configuration to setup a Thug honeyclient VM☆20Updated 10 years ago
- Flow-Indexer indexes flows found in chunked log files from bro,nfdump,syslog, or pcap files☆44Updated 9 months ago
- A Docker container for Cowrie - SSH honeypot based on kippo☆10Updated 9 years ago
- module for osquery to load Bro logs into tables☆28Updated 9 years ago
- Web of trust grapher☆39Updated this week
- The Auditd Framework logs and applies security policy to linux auditd data☆15Updated 7 years ago
- MISP - Ansible installation script☆22Updated 6 years ago
- Convert libvirt-QEMU-save (LQS) files to raw memory files☆37Updated last year
- Generates visualizations from the output of flow tools such as SiLK.☆35Updated 8 years ago
- A tool to generate log messages related to interfaces, neighbor cache (ARP,NDP), IP address, routing, FIB rules, traffic control.☆32Updated 4 months ago
- Time-Machine Dynamic Bulk Packet Recorder☆36Updated last year
- Connectors for the Zeek NetControl framework☆19Updated 3 weeks ago
- A library and a tool for converting audit logs to XML and JSON☆45Updated 7 years ago
- Bro/Zeek integration with osquery☆94Updated 4 years ago
- A program that uses xapian to index the flat file databases used by nfdump or flow-tools☆36Updated 6 years ago
- IDS Utility Belt For Automating/Testing Various Things☆30Updated 4 years ago
- An active domain name query tool to help keep track of domain name movements...☆15Updated 3 years ago
- Top DNS Measurement for Bro☆11Updated 4 years ago
- viewssld is a free, open source, non-terminating SSLv2/SSLv3/TLS traffic decryption daemon for Snort, and other Network Intrusion Detecti…☆74Updated 7 years ago
- Honeypot log processor to create OTX Pulse entries☆29Updated last year
- splunk alert script to create resilient tickets☆10Updated 8 years ago
- Puppet module for Auditd☆40Updated 4 years ago
- bro.vim - A simple plugin for working with the bro scripting languages.☆22Updated 5 years ago
- Validate if afpacket PACKET_FANOUT_HASH is working properly☆25Updated 2 years ago
- Cuckoo Sandbox Local Maltego Transforms Project☆49Updated 10 years ago