matthoffman / degas
DGA-generated domain detection using deep learning models
☆23Updated 2 years ago
Alternatives and similar repositories for degas:
Users that are interested in degas are comparing it to the libraries listed below
- DGA Domain Detection using Bigram Frequency Analysis☆53Updated 7 years ago
- DGA Domains detection☆62Updated 6 years ago
- A collection of known Domain Generation Algorithms☆66Updated 8 years ago
- Cyber Threat Intelligence Feeds☆89Updated 8 years ago
- A completely automated anomaly detector Zeek network flows files (conn.log).☆75Updated 5 months ago
- Zeek support for Community ID flow hashing.☆35Updated last year
- GQUIC Protocol Analyzer for Zeek (Bro) Network Security Monitor☆75Updated last year
- Passive DNS Common Output Format☆36Updated 5 months ago
- Classifier to separate legitimate domains from those generated by a domain generating algorithm (DGA).☆41Updated 8 years ago
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆31Updated 4 months ago
- The repository that contains the algorithms for generating domain names, dictionaries of malicious domain names. Developed to research th…☆218Updated 7 years ago
- Zeek plugin to generate data on per-packet sizes and intervals☆14Updated 4 years ago
- DGA Detective - Hunt domains generated by Domain Generation Algorithms to identify malware traffic☆39Updated 5 months ago
- Detect cryptocurrency mining traffic with Zeek.☆46Updated 3 years ago
- Utility for parsing Bro log files into CSV or JSON format☆41Updated 2 years ago
- Client API to query any Passive DNS implementation following the Passive DNS - Common Output Format.☆76Updated this week
- Definition, description and relationship types of MISP objects☆94Updated last week
- Debian and Red Hat packaging for SIE DNS sensor☆15Updated last year
- A web-based tool to assist the work of the intuitive threat analysts.☆112Updated 5 years ago
- A mapping of used malware names to commonly known family names☆62Updated last year
- Specifications used in the MISP project including MISP core format☆51Updated 3 weeks ago
- This project contains code for comparing or ranking APT capabilities and operational capacity. The metrics are meant to quantify, rank, o…☆35Updated 5 years ago
- This python scripts can calculate the WHOIS Similarity Distance between two given domains.☆30Updated 2 years ago
- Collection of data sources that can be used to provide context to security events☆25Updated 9 years ago
- CyCAT.org API back-end server including crawlers☆30Updated last year
- Suspicious DGA from PDNS and Sandbox.☆183Updated 2 years ago
- Malware Sinkhole List in various formats☆102Updated 2 years ago
- server for indexing and querying passive DNS observations☆45Updated last year
- A Spicy protocol analyzer for WireGuard☆29Updated 4 years ago
- Last download from git://git.carnivore.it/honeytrap.git of Honytrap by Tillmann Werner☆43Updated 3 years ago