gonids is a library to parse IDS rules, with a focus primarily on Suricata rule compatibility. There is a discussion forum available that you can join on Google Groups: https://groups.google.com/forum/#!topic/gonids/
☆192Jul 18, 2025Updated 7 months ago
Alternatives and similar repositories for gonids
Users that are interested in gonids are comparing it to the libraries listed below
Sorting:
- Go Client for Suricata (Interacting via Socket)☆13Aug 23, 2020Updated 5 years ago
- suricata eve.json parser in Go☆15May 16, 2019Updated 6 years ago
- fast, extensible, versatile event router for Suricata's EVE-JSON format☆57Nov 20, 2025Updated 3 months ago
- Golang library that implements a sigma log rule parser and match engine.☆104Jul 17, 2024Updated last year
- Suricata, Snort and Zeek IDS rule and pcap testing system☆512Feb 17, 2026Updated last week
- A Yara Lua output script for Suricata☆20Apr 7, 2019Updated 6 years ago
- Suricata安装部署&丢包优化&性能调优&规则调整&Pfring设置☆143Oct 14, 2019Updated 6 years ago
- Scirius is a web application for Suricata ruleset management and threat hunting.☆673Dec 23, 2025Updated 2 months ago
- Go implementation of the Community ID flow hashing standard☆21Apr 17, 2025Updated 10 months ago
- Community-based CybergON-powered Suricata rules☆12Jul 5, 2022Updated 3 years ago
- dpdk infrastructure for software acceleration. Currently working on RX and ACL pre-filter☆90Mar 10, 2021Updated 4 years ago
- Collection of various open-source an commercial rulesets for NIDS (especially for Suricata and Snort)☆29Jul 24, 2023Updated 2 years ago
- A Go(lang) IDS rule parser☆13Jun 10, 2019Updated 6 years ago
- Enables dynamic translation of structured data between formats☆14Dec 14, 2018Updated 7 years ago
- server for indexing and querying passive DNS observations☆50Jan 12, 2026Updated last month
- Application layer protocol identification of traffic flows☆225Nov 6, 2022Updated 3 years ago
- Testimony is a single-machine, multi-process architecture for sharing AF_PACKET data across processes, allowsing packets to be copied fro…☆109Aug 6, 2021Updated 4 years ago
- INACTIVE - http://mzl.la/ghe-archive - Zeek Extreme Performance Tuning☆26Oct 10, 2019Updated 6 years ago
- Suricata rules for network anomaly detection☆184Feb 7, 2026Updated 3 weeks ago
- ☆35Dec 9, 2023Updated 2 years ago
- Validate if afpacket PACKET_FANOUT_HASH is working properly☆25May 19, 2022Updated 3 years ago
- Simple file system integrity checking tooling.☆112Dec 29, 2025Updated last month
- Plugin providing native AF_Packet support for Zeek.☆33Oct 22, 2025Updated 4 months ago
- NTP logger/honeypot☆55Mar 27, 2014Updated 11 years ago
- Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search☆485Feb 19, 2026Updated last week
- Suricata RPMs for CentOS/RHEL and Fedora☆19Jan 13, 2026Updated last month
- CLI and Go package for fast, offline ASN lookups☆20Feb 27, 2025Updated last year
- Accurate, modular, scalable PCAP manipulation tool written in Go.☆96Apr 30, 2024Updated last year
- Meer is a "spooler" for Suricata / Sagan.☆30Jun 21, 2023Updated 2 years ago
- Quickly generate suricata rules for IOCs☆28Apr 30, 2021Updated 4 years ago
- Simple tool to monitor network changes over time and trigger alerts☆15Mar 11, 2020Updated 5 years ago
- CIDR to IP List Tool☆14Mar 12, 2016Updated 9 years ago
- Suricata JSON schema project☆12Jan 5, 2020Updated 6 years ago
- gojacego is a calculation engine for Golang.☆12May 1, 2025Updated 9 months ago
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆37Nov 9, 2022Updated 3 years ago
- Plugin providing AF_XDP support for Bro.☆14May 10, 2021Updated 4 years ago
- Suricata Extreme Performance Tuning guide☆213Mar 15, 2018Updated 7 years ago
- Meer (GPLv2) is a dedicated "spooler" for the Suricata & Sagan EVE output formats.☆23Feb 9, 2021Updated 5 years ago
- The Data Analysis Pipeline☆17Apr 23, 2019Updated 6 years ago