This repository has been archived in favor of https://github.com/idaholab/Malcolm-Test-Artifacts
☆37Dec 11, 2024Updated last year
Alternatives and similar repositories for Malcolm-PCAP
Users that are interested in Malcolm-PCAP are comparing it to the libraries listed below
Sorting:
- Log4j Exploit Detection Logic for Zeek☆19Nov 25, 2025Updated 3 months ago
- ☆21Oct 16, 2021Updated 4 years ago
- Exploit funcionales para pruebas de seguridad en entornos industriales☆11Jul 8, 2020Updated 5 years ago
- Zeek Ethernet/IP and CIP Parser - CISA ICSNPP☆26Nov 6, 2025Updated 3 months ago
- Industrial Control Systems Network Protocol Parsers☆189Sep 4, 2025Updated 5 months ago
- Dockerized Zeek☆12Mar 9, 2024Updated last year
- Simple packet dissector that detects anomalous DNP3 traffic by analysing its parameters☆15Jan 12, 2016Updated 10 years ago
- Enables Zeek to communicate with Tenzir☆11Jul 20, 2023Updated 2 years ago
- This module detects HTTP requests that are non RFC compliant and used for smuggling☆12Mar 16, 2023Updated 2 years ago
- Cloud security documents and tools to assist with conducting risk assessments that conform to the ICS62443 guidelines☆11Apr 24, 2023Updated 2 years ago
- Extensions for Zeek's Intelligence Framework.☆11Mar 1, 2022Updated 4 years ago
- Updates the Emerging Threats open ruleset for Suricata☆10Sep 20, 2015Updated 10 years ago
- Bro PCAP Processing and Tagging API☆28Nov 9, 2017Updated 8 years ago
- DHCP Fingerprinting☆31Dec 15, 2020Updated 5 years ago
- PacketSled's Bro AMQP Writer Plugin☆11Aug 5, 2016Updated 9 years ago
- line based tcp load balancing proxy.☆14Jun 18, 2024Updated last year
- Attempt to replicate the functions of auto_rip by Corey Harrell in Python.☆12Aug 4, 2024Updated last year
- Scripts and small programs that are packaged into termux's termux-tools package☆12Jan 23, 2026Updated last month
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆32Updated this week
- A Microsoft Threat Modelling tool template for ICS threat modelling☆13Aug 20, 2020Updated 5 years ago
- ICS/OT related Wireshark profiles + adding some other (IT or OT related) Open Source Wireshark Profiles☆18Mar 21, 2025Updated 11 months ago
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆32Sep 16, 2024Updated last year
- ☆14Sep 29, 2015Updated 10 years ago
- Zeek plugin to generate data on per-packet sizes and intervals☆14Apr 21, 2020Updated 5 years ago
- A proof of concept implementation of the Siemens S7 protocol analyser for the Bro IDS.☆16Mar 26, 2017Updated 8 years ago
- phenix is an orchestration tool and GUI for Sandia's minimega platform☆23Feb 10, 2026Updated 2 weeks ago
- Plugin providing native AF_Packet support for Zeek.☆33Oct 22, 2025Updated 4 months ago
- ICS security resources☆127May 7, 2025Updated 9 months ago
- Zeek support for Community ID flow hashing.☆36Jul 11, 2023Updated 2 years ago
- ☆18Dec 20, 2024Updated last year
- A repository for development of the TAXII Specifications. For official releases, please see http://taxiiproject.github.io/releases/☆41Nov 29, 2015Updated 10 years ago
- High performance time ordered PCAP merging utility☆23Jun 20, 2022Updated 3 years ago
- A package manager for Zeek☆47Jan 8, 2026Updated last month
- PowerShell script for hardening GE digital CIMPLICITY servers☆23Aug 12, 2021Updated 4 years ago
- ☆22Oct 21, 2024Updated last year
- The Distributed Network Protocol Library for Scapy☆23Nov 22, 2023Updated 2 years ago
- C37.118.2-2011 Synchrophasor Protocol Parser and Tools in Python3☆21Mar 10, 2021Updated 4 years ago
- Zeek package for detecting the Eternal* exploits and a set of SMBv1 protocol violations.☆19Aug 21, 2025Updated 6 months ago
- Example Suricata rules implementing some of my detection tactics☆22Jan 13, 2023Updated 3 years ago