kotlaluk / spl-parser
Parser for Splunk's Search Processing Language (SPL) syntax highlighting
☆17Updated 4 years ago
Alternatives and similar repositories for spl-parser:
Users that are interested in spl-parser are comparing it to the libraries listed below
- OSSEM Common Data Model☆55Updated 2 years ago
- Zeek support for Community ID flow hashing.☆35Updated last year
- A Zeek package that detects Zoom logins and meeting joins☆12Updated 4 years ago
- Cisco Orbital - Osquery queries by Talos☆129Updated 5 months ago
- Firepit - STIX Columnar Storage☆16Updated 7 months ago
- Strelka Web UI for File Submission and Analysis☆62Updated 5 months ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for…☆35Updated 2 years ago
- Simple parser for Splunk Processing Language (SPL) written in Python.☆35Updated 6 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 months ago
- Hosted analyzers built for Grapl☆13Updated 2 years ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆50Updated 2 years ago
- This repository contains generated contextual data utilized by pyattck.☆18Updated 6 months ago
- Threat Detection Rules (Snort/Sigma/Yara)☆13Updated last year
- Custom Splunk search command to reconstruct a pstree from Sysmon process creation events (EventCode 1)☆23Updated last year
- Bluehat 2018 Graphs for Security Workshop☆42Updated 6 years ago
- Synthetic Adversarial Log Objects: A Framework for synthentic log generation☆77Updated last year
- ☆33Updated 3 years ago
- pySigma Cookiecutter backend template☆21Updated 2 months ago
- A CALDERA plugin☆74Updated 2 months ago
- Automated deployment of MISP and MISP-Dashboard via K8S and AWS☆19Updated 5 years ago
- OCA-wide documentation shared by all sub-projects and repositories☆33Updated 3 months ago
- An elevated STIX representation of the MITRE ATT&CK Groups knowledge base☆23Updated 2 years ago
- Various blog post projects.☆10Updated 7 months ago
- Web app that provides basic navigation and annotation of ATT&CK matrices☆16Updated 4 years ago
- A MITRE Caldera plugin☆40Updated 2 months ago
- ☆218Updated last year
- MITRE ATT&CK in CSV form☆18Updated last year
- Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)☆97Updated 2 weeks ago
- Open source endpoint agent providing host information to Zeek. [v2]☆72Updated 3 months ago
- Phantom Apps Repo☆82Updated 3 years ago