hardenedlinux / hardenedlinux-zeek-scripts
☆37Updated last year
Alternatives and similar repositories for hardenedlinux-zeek-scripts:
Users that are interested in hardenedlinux-zeek-scripts are comparing it to the libraries listed below
- ThreatHound is a threat intelligence query tool use for detecting potentially malicious IP or domains. It combines the MISP open source t…☆39Updated 5 years ago
- 《横向移动攻击与检测技术》专栏文章☆16Updated 5 years ago
- suricata IDS的规则,测试在用的,部分自写的规则视情况放出。☆18Updated 5 years ago
- 威胁检测规则集☆15Updated 5 years ago
- ATT&CK技战术数据☆16Updated 4 years ago
- ☆24Updated 5 years ago
- 天御攻防实验室 - 威胁猎杀实战系列☆102Updated 5 years ago
- Oops, It's funny to detect a webshell. Temporarily not maintained☆18Updated 7 years ago
- 一个HIDS agent端的demo☆17Updated 5 years ago
- A Solution For Cross-Platform Obfuscated Commands Detection presented on CIS2019 China. 动静态Bash/CMD/PowerShell命令混淆检测框架 - CIS 2019大会☆163Updated 5 years ago
- ☆11Updated 5 years ago
- Treck Network Stack Discovery Tool by JSOF☆32Updated 4 years ago
- A golang client of our webshell scanner API☆28Updated 7 years ago
- tcppc: A simple honeypot to capture TCP/TLS/UDP payloads on ALL ports.☆35Updated 4 years ago
- Explore Indicators of Compromise Automatically☆94Updated 5 years ago
- The python client of passivedns.cn☆98Updated 6 years ago
- ☆30Updated last year
- ☆54Updated 8 months ago
- Useful resources for Zeek(https://zeek.org/) (Bro(http://bro.org/))☆31Updated 4 years ago
- ☆9Updated 8 years ago
- nmap service and application version detection (without nmap installation)☆113Updated 7 years ago
- A dsniff project using bro☆10Updated 9 years ago
- Snort rules☆35Updated 6 years ago
- acunetix☆63Updated 4 years ago
- check_IP is to judge whether a IP is malicious based on open threat intelligence,基于开源威胁情报AlienVault,排查IP地址及域名的恶意性☆52Updated 6 years ago
- Python nbtstat + smb_version without third party packages☆30Updated 3 years ago
- webshell and nonwebshell samples,which can be used to train machine learning models to detect webshell☆43Updated 5 years ago
- A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.☆33Updated 2 years ago
- Application and service identification rules for Suricata☆29Updated 2 years ago
- 基于Flink实现实时冰蝎(Behinder)流量检测☆40Updated 5 years ago