hosom / file-extraction
Extract files from network traffic with Zeek.
☆100Updated 4 years ago
Alternatives and similar repositories for file-extraction:
Users that are interested in file-extraction are comparing it to the libraries listed below
- Various Bro scripts☆96Updated 8 years ago
- Bro scripts to be shared with the community☆109Updated 11 years ago
- ☆76Updated 2 years ago
- Contributed Bro Scripts☆30Updated 10 years ago
- Bro scripts written by CrowdStrike Services☆146Updated 3 years ago
- Misc. Bro scripts☆63Updated 7 years ago
- Scripts for Bro IDS and ELK Stack☆56Updated 9 years ago
- Analysis scripts for the Bro Intrusion Detection System☆59Updated 10 years ago
- This repository contains all public indicators identified by 401trg during the course of our investigations. It also includes relevant ya…☆121Updated 3 years ago
- ☆85Updated 11 years ago
- IOC (Indicator of Compromise) Extractor: a program to help extract IOCs from text files.☆135Updated 9 years ago
- Malware/IOC ingestion and processing engine☆104Updated 6 years ago
- CIF v3 -- the fastest way to consume threat intelligence☆183Updated last year
- QRadio ~ Best Threat Intelligence Radio ~ Tune In!☆96Updated 8 years ago
- ☆72Updated 3 years ago
- Rule sets for Sagan☆102Updated 4 years ago
- ☆169Updated 3 years ago
- Mapping NSM rules to MITRE ATT&CK☆68Updated 4 years ago
- Network Forensics Bro scripts & pcap samples☆62Updated 10 years ago
- Bro/Zeek integration with osquery☆94Updated 4 years ago
- Bro-IDS scripts☆50Updated 8 years ago
- Passive DNS collection using Zeek☆182Updated last year
- Detect cryptocurrency mining traffic with Zeek.☆46Updated 3 years ago
- Bro IDS + ELK Stack to detect and block data exfiltration☆47Updated 6 years ago
- Django web interface for managing Yara rules☆190Updated 6 years ago
- Python abstract API for PassiveTotal services in the form of libraries and command line utilities.☆85Updated last year
- This repository will hold PCAP IOC data related with known malware samples (owner: Bryant Smith)☆100Updated 3 years ago
- TIH is an intelligence tool that helps you in searching for IOCs across multiple openly available security feeds and some well known APIs…☆149Updated 8 months ago
- A web-based tool to assist the work of the intuitive threat analysts.☆112Updated 5 years ago
- Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings☆122Updated 3 years ago