zeek-scripts
☆44Dec 27, 2018Updated 7 years ago
Alternatives and similar repositories for zeek-scripts
Users that are interested in zeek-scripts are comparing it to the libraries listed below
Sorting:
- A set of zeek scripts providing a module for tracking and correlating abnormal DNS behavior.☆35Jan 4, 2025Updated last year
- 威胁检测规则集☆15Jul 5, 2019Updated 6 years ago
- A Zeek log writer plugin that publishes to Kafka.☆53Aug 18, 2025Updated 6 months ago
- A completely automated anomaly detector Zeek network flows files (conn.log).☆82Aug 5, 2025Updated 7 months ago
- Plugin providing native AF_Packet support for Zeek.☆33Oct 22, 2025Updated 4 months ago
- Remote Desktop Client Fingerprint script for Zeek. Based off of https://github.com/0x4D31/fatt☆40Jun 20, 2023Updated 2 years ago
- Bro IDS programs collection.☆146Oct 16, 2019Updated 6 years ago
- 用于辅助安全工程师漏洞挖掘、测试、复现,集合了mock、httplog、dns tools、xss,可用于测试各类无回显、无法直观判断或特定场景下的漏洞。☆11Apr 2, 2021Updated 4 years ago
- Ripple20 Critical Vulnerabilities - Detection Logic and Signatures☆12May 28, 2021Updated 4 years ago
- Top DNS Measurement for Bro☆10Aug 22, 2020Updated 5 years ago
- A Zeek package that detects Zoom logins and meeting joins☆12Apr 15, 2020Updated 5 years ago
- Treck Network Stack Discovery Tool [Ripple20]☆12Jul 1, 2020Updated 5 years ago
- some config files☆14Feb 23, 2026Updated last week
- ☆38Nov 2, 2024Updated last year
- Fixes and patches☆20Dec 3, 2020Updated 5 years ago
- Threat Simulator for Enterprise Networks☆14May 14, 2022Updated 3 years ago
- Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings☆122Jul 12, 2021Updated 4 years ago
- A set of Zeek scripts to detect ATT&CK techniques.☆621Jun 26, 2024Updated last year
- ☆57Dec 15, 2020Updated 5 years ago
- ☆14Oct 25, 2022Updated 3 years ago
- Detecting PowerShell Empire, Metasploit Meterpreter and Cobalt Strike agents by payload size sequence analysis and host correlation☆15Aug 17, 2018Updated 7 years ago
- Windows log and threat hunting with powershell☆16Dec 11, 2020Updated 5 years ago
- Zeek Training Materials/Products☆41Feb 2, 2026Updated last month
- How to Zeek Sysmon Logs!☆103Feb 12, 2022Updated 4 years ago
- Minimal version for https://github.com/zmap/zgrab.☆16Sep 17, 2022Updated 3 years ago
- Repository collecting and automagically processing public threat intelligence reports.☆18May 1, 2020Updated 5 years ago
- An Ansible playbook for deploying the Suricata intrusion detection system and fetching Snort rules with Oinkmaster.☆17Oct 30, 2021Updated 4 years ago
- Heartbleed test script for OpenVPN☆34Apr 10, 2014Updated 11 years ago
- ☆39Dec 4, 2023Updated 2 years ago
- ☆75Apr 3, 2025Updated 11 months ago
- Zeek support for Community ID flow hashing.☆36Jul 11, 2023Updated 2 years ago
- ☆18Dec 20, 2024Updated last year
- Sniffpass will alert on cleartext passwords discovered in HTTP POST requests☆17Oct 30, 2023Updated 2 years ago
- Bro integration with osquery☆15Mar 24, 2023Updated 2 years ago
- 红蓝对抗交流心得☆106Apr 8, 2020Updated 5 years ago
- A Yara Lua output script for Suricata☆20Apr 7, 2019Updated 6 years ago
- ☆24Jan 19, 2020Updated 6 years ago
- TAXII Server supporting the 2.1 spec.☆20Mar 30, 2020Updated 5 years ago
- incident response scripts☆18Mar 4, 2019Updated 7 years ago