jakewarren / suricata-rule-generator
Quickly generate suricata rules for IOCs
☆29Updated 4 years ago
Alternatives and similar repositories for suricata-rule-generator:
Users that are interested in suricata-rule-generator are comparing it to the libraries listed below
- ☆43Updated 2 years ago
- Threat Mapping Catalogue☆17Updated 3 years ago
- Collection of Suricata rule sets that I use modified to my environments.☆39Updated 4 years ago
- Suricata rule and intel index☆30Updated last month
- A Yara Lua output script for Suricata☆20Updated 6 years ago
- How to Zeek Sysmon Logs!☆101Updated 3 years ago
- ☆35Updated last year
- Useful resources for Zeek(https://zeek.org/) (Bro(http://bro.org/))☆31Updated 5 years ago
- Look into EDR events from network☆23Updated this week
- The Fastest way to consume Threat Intel☆25Updated 3 years ago
- alertflex controller☆10Updated last month
- Mapping NSM rules to MITRE ATT&CK☆71Updated 4 years ago
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆70Updated 3 weeks ago
- ☆33Updated 3 years ago
- Globally distributed honeypots and HoneyNets IOCs and file reversing☆16Updated last year
- Bro integration with osquery☆15Updated 2 years ago
- Golang based web service to scan files with yara rules☆27Updated 7 years ago
- collector/runner☆65Updated last month
- Check IOC provided by a MISP instance on Suricata events☆17Updated 5 years ago
- Tool to read EVTX files including SYSMON and convert to JSON, MISP Objects and Graph stream☆11Updated 4 years ago
- Ripple20 Critical Vulnerabilities - Detection Logic and Signatures☆12Updated 3 years ago
- Collect autorun records from running system☆61Updated 3 years ago
- Bro analyzer that detects Google's QUIC protocol☆10Updated 4 years ago
- Remote Desktop Client Fingerprint script for Zeek. Based off of https://github.com/0x4D31/fatt☆39Updated last year
- go-atomicredteam is a Golang application to execute tests as defined in the atomics folder of Red Canary's Atomic Red Team project (https…☆49Updated 2 years ago
- ATT&CK Evaluations website (DEPRECATED)☆59Updated 4 years ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆35Updated 2 years ago
- This tool maps a file's behavior on MITRE ATT&CK matrix.☆59Updated 5 years ago
- Citrix ADC (NetScaler) Honeypot. Supports detection for CVE-2019-19781 and login attempts☆26Updated 5 years ago
- Application and service identification rules for Suricata☆29Updated 2 years ago