jakewarren / suricata-rule-generatorLinks
Quickly generate suricata rules for IOCs
☆29Updated 4 years ago
Alternatives and similar repositories for suricata-rule-generator
Users that are interested in suricata-rule-generator are comparing it to the libraries listed below
Sorting:
- alertflex controller☆10Updated 3 months ago
- How to Zeek Sysmon Logs!☆102Updated 3 years ago
- ☆43Updated 2 years ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆35Updated 2 years ago
- ☆34Updated 3 years ago
- A Yara Lua output script for Suricata☆20Updated 6 years ago
- Collection of Suricata rule sets that I use modified to my environments.☆39Updated 4 years ago
- Suricata rule and intel index☆31Updated 2 months ago
- Useful resources for Zeek(https://zeek.org/) (Bro(http://bro.org/))☆31Updated 5 years ago
- The Fastest way to consume Threat Intel☆25Updated 3 years ago
- Threat Mapping Catalogue☆17Updated 3 years ago
- A Beat that monitors a local Nessus reports directory and outputs scan results to Elasticsearch or Logstash.☆31Updated 7 years ago
- Audit Powershell and search from known keywords in history #Blueteam☆25Updated 5 years ago
- Mapping NSM rules to MITRE ATT&CK☆71Updated 4 years ago
- Bro integration with osquery☆15Updated 2 years ago
- YETI (Your Everyday Threat Intelligence) Integration to Elastic Stack☆16Updated 4 years ago
- Ripple20 Critical Vulnerabilities - Detection Logic and Signatures☆12Updated 4 years ago
- Website crawler with YARA detection☆88Updated last year
- ☆35Updated last year
- Configuring the Suricata IDS to detect DoS attacks by adding custom rule file.☆39Updated 5 years ago
- Golang based web service to scan files with yara rules☆26Updated 7 years ago
- WebLogic Honeypot is a low interaction honeypot to detect CVE-2017-10271 in the Oracle WebLogic Server component of Oracle Fusion Middlew…☆32Updated 5 years ago
- Windows GUI/Execution Engine for Atomic Red Team Atomics☆34Updated 5 years ago
- ☆20Updated 4 years ago
- Look into EDR events from network☆23Updated last month
- A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.☆33Updated 2 years ago
- Last download from git://git.carnivore.it/honeytrap.git of Honytrap by Tillmann Werner☆43Updated 3 years ago
- go-atomicredteam is a Golang application to execute tests as defined in the atomics folder of Red Canary's Atomic Red Team project (https…☆49Updated 2 years ago
- Collect autorun records from running system☆60Updated 3 years ago
- Scripts to detect Fast-Flux and DGA using DNS query responses☆43Updated 8 years ago