josh-thurston / easyBEATS
Beats for Raspberry Pi / ARM
☆84Updated 3 years ago
Alternatives and similar repositories for easyBEATS:
Users that are interested in easyBEATS are comparing it to the libraries listed below
- Installation script for ELK stack to make life easy.☆69Updated 4 years ago
- elasticsearch, logstash and kibana configuration for pi-hole visualiziation☆205Updated 2 years ago
- ☆37Updated 5 years ago
- Logstash configuration for pfSense syslog events.☆94Updated last year
- Zeek (formerly Bro) Network Security Monitor package for pfSense router/firewall☆44Updated 3 years ago
- Parse wazuh[HIDS] alerts into ECS mapping using Filebeat☆27Updated 4 years ago
- Cisco eStreamer client☆25Updated 2 years ago
- Experimental DNS logs pipeline based on Pi-hole dnsmasq logs, ELK stack, and Filebeat. Sample configs included.☆30Updated last year
- Translate an ECS mapping CSV to starter pipelines for Beats, Elasticsearch or Logstash☆54Updated 2 years ago
- Docker files for building Zeek.☆86Updated last year
- MISP Docker (XME edition)☆283Updated last year
- Splunk Add on for OPNsense firewall☆1Updated 3 months ago
- Wazuh - Splunk App☆51Updated 4 months ago
- Run zeek with zeekctl in docker☆51Updated 4 months ago
- splunksecrets is a tool for working with Splunk secrets offline☆45Updated 2 months ago
- Elastic Beat for fetching and shipping Office 365 audit events☆66Updated 4 years ago
- Ansible playbook for installing MineMeld on Linux☆48Updated 3 years ago
- Graylog Processing Pipeline functions to enrich log messages with IoC information from threat intelligence databases☆151Updated 10 months ago
- This program exports MITRE ATT&CK framework in ELK dashboard☆78Updated 2 years ago
- This package allows the use of a custom Elastalert Alert which creates alerts with observables in TheHive using TheHive4Py.☆27Updated 3 years ago
- Configuration for a Palo Alto Networks fed ELK Stack with Visualizations☆74Updated 5 years ago
- Integrate Zeek with Alienvault OTX☆25Updated 4 years ago
- Synapse: a Meta Alert Feeder for TheHive, a Security Incident Response Platform☆71Updated last year
- SIEM Logstash parsing for more than hundred technologies☆182Updated 2 months ago
- Automated Docker MISP container - Malware Information Sharing Platform and Threat Sharing☆105Updated last year
- ☆29Updated 3 years ago
- MineMeld nodes for MISP☆18Updated 11 months ago
- Threat Intelligence with Elastic - Minemeld integration with Elasticsearch☆19Updated 3 years ago
- Risk Based Alerting Supporting Add-On (SA) for Splunk☆45Updated 3 years ago