hhzzk / dns-tunnelsLinks
☆14Updated 4 years ago
Alternatives and similar repositories for dns-tunnels
Users that are interested in dns-tunnels are comparing it to the libraries listed below
Sorting:
- Bro IDS + ELK Stack to detect and block data exfiltration☆46Updated 6 years ago
- Rule sets for Sagan☆105Updated 4 years ago
- Malware Sinkhole List in various formats☆102Updated 3 years ago
- brostash: Linux distribution based on Debian and focusing on network security events collection☆34Updated 4 years ago
- Python abstract API for PassiveTotal services in the form of libraries and command line utilities.☆85Updated 2 years ago
- Sniffles: Packet Capture Generator for IDS and Regular Expression Evaluation☆63Updated 4 years ago
- How to Zeek Sysmon Logs!☆102Updated 3 years ago
- scan-detection policies for bro☆16Updated 6 months ago
- Wireshark plugin to display Suricata analysis info☆95Updated 3 years ago
- ☆53Updated 6 years ago
- Detect HTTP stalling attacks like slowloris with Bro☆19Updated 7 years ago
- Detecting Lateral Movement with Machine Learning☆138Updated 7 years ago
- Plugin providing AF_XDP support for Bro.☆14Updated 4 years ago
- ☆14Updated last year
- Passive DNS collection using Zeek☆182Updated 2 years ago
- Passive DNS V2☆60Updated 11 years ago
- Bro integration with osquery☆15Updated 2 years ago
- Malware/IOC ingestion and processing engine☆106Updated 6 years ago
- JoeSandbox-Bro is a simple bro script which extracts files from your internet connection and analyzes them automatically on Joe Sandbox☆45Updated 6 years ago
- ☆75Updated 3 years ago
- ☆35Updated last year
- Extract files from network traffic with Zeek.☆101Updated 5 years ago
- collector/runner☆65Updated 4 months ago
- ☆41Updated 2 years ago
- a network packet capture compiler☆201Updated 3 years ago
- A low interaction honeypot for the Cisco ASA component capable of detecting CVE-2018-0101, a DoS and remote code execution vulnerability.☆52Updated 6 years ago
- ☆10Updated 9 years ago
- Repository for my ATT&CK analysis research.☆69Updated 6 years ago
- A lightweight tool to load Windows Event Log evtx files into Elasticsearch.☆117Updated 4 years ago
- viewssld is a free, open source, non-terminating SSLv2/SSLv3/TLS traffic decryption daemon for Snort, and other Network Intrusion Detecti…☆74Updated 7 years ago