jay-johnson / spylunking
Drill down into your python logs using JSON logs stored in Splunk - supports sending over TCP or the Splunk HEC REST API handlers (using threads or multiprocessing) - includes a pre-configured Splunk sandbox in a docker container
☆12Updated 2 years ago
Alternatives and similar repositories for spylunking:
Users that are interested in spylunking are comparing it to the libraries listed below
- Data Governance app for Splunk☆12Updated last year
- A terraform module for deploying Tenable.io's preauthorized Nessus Scanner in AWS☆34Updated last year
- A set of AWS resources for testing the Log4Shell vulnerability, deployable with terraform☆12Updated 3 years ago
- A few quick recipes for those that do not have much time during the day☆22Updated 4 months ago
- A Zeek package that detects Zoom logins and meeting joins☆12Updated 4 years ago
- Python tool build around GreyNoise's alpha/public API☆10Updated 6 years ago
- ☆25Updated 6 years ago
- Core incident handling plugins for aws_ir cli, incident pony, and more.☆21Updated 6 years ago
- Integration for Jira ticket creation from Tenable vulnerability scans☆17Updated 5 years ago
- Streaming web crawler with WebSocket API☆44Updated last year
- This script is used to generate some basic detections of the aws security services☆72Updated 3 years ago
- Python bindings for Yeti's API☆18Updated last year
- S3Insights is a platform for efficiently deriving security insights about S3 data through metadata analysis☆12Updated 3 months ago
- Manage GuardDuty At Enterprise Scale☆22Updated 4 years ago
- Move frozen buckets to AWS S3 (and ultimately Glacier) for long term storage☆12Updated 7 years ago
- Materials for the BSides NoVA/Charleston 2018 Bro Workshop☆14Updated this week
- Simple tool to identify and remediate the use of the AWS EC2 IMDSv1.☆16Updated 3 years ago
- Machine readable cybersecurity compliance standards library for Python, starting with FISMA and NIST Risk Management Framework☆59Updated 4 years ago
- Bluehat 2018 Graphs for Security Workshop☆42Updated 6 years ago
- Following repository contains source codes used in my two Books.☆11Updated 9 years ago
- Splunk scripted input for opening a backconnect shell on a remote forwarder☆45Updated 4 years ago
- ☆11Updated 6 years ago
- Remotely collect linux live forensics artifacts.☆13Updated 2 years ago
- Send events from G Suite to McAfee SIEM☆13Updated 5 years ago
- Serverless, real-time, ClamAV+Yara scanning for your S3 Buckets☆31Updated 9 months ago
- Parser for Splunk's Search Processing Language (SPL) syntax highlighting☆19Updated 5 years ago
- Active Response plugin. Osquery to execute wazuh/ossec active response plugins. You can write your own plugins, easy to plug☆9Updated 4 years ago
- The official Prelude-Correlator GitHub mirror of https://www.prelude-siem.org/projects/prelude-correlator/repository☆10Updated 3 years ago
- Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, S…☆16Updated 3 years ago
- Manage your security groups using the API gateway and Lambda☆19Updated 8 years ago