mole-ids / mole
Yara powered NIDS with high speed packet capture powered by PF_RING
☆68Updated 9 months ago
Alternatives and similar repositories for mole:
Users that are interested in mole are comparing it to the libraries listed below
- Accurate, modular, scalable PCAP manipulation tool written in Go.☆87Updated 9 months ago
- APIs for generating STIX 2.1 and TAXII 2.1 messages with Go (Golang)☆52Updated 2 months ago
- Go implementation of the Community ID flow hashing standard☆20Updated last month
- How to Zeek Sysmon Logs!☆102Updated 3 years ago
- simple YARA-based IOC scanner☆166Updated last week
- ☆164Updated 2 years ago
- Zeek IDS Dockerfile☆100Updated 2 years ago
- Rule sets for Sagan☆102Updated 4 years ago
- go-atomicredteam is a Golang application to execute tests as defined in the atomics folder of Red Canary's Atomic Red Team project (https…☆49Updated last year
- A Go implementation and parser for Sigma rules.☆86Updated 5 months ago
- Golang Parser for Microsoft Event Logs☆101Updated last month
- This repository will hold PCAP IOC data related with known malware samples (owner: Bryant Smith)☆100Updated 3 years ago
- gyp: A pure Go YARA parser☆106Updated 11 months ago
- gonids is a library to parse IDS rules, with a focus primarily on Suricata rule compatibility. There is a discussion forum available that…☆183Updated 2 years ago
- Collect autorun records from running system☆60Updated 3 years ago
- Golang library that implements a sigma log rule parser and match engine.☆94Updated 7 months ago
- fast, extensible, versatile event router for Suricata's EVE-JSON format☆51Updated 7 months ago
- Passive DNS collection using Zeek☆182Updated last year
- Mapping NSM rules to MITRE ATT&CK☆69Updated 4 years ago
- Freki is a tool to manipulate packets in usermode using NFQUEUE and golang.☆58Updated 2 years ago
- A Go implementation of JARM☆119Updated 2 years ago
- A lightweight tool to score network traffic and flag anomalies☆122Updated 6 months ago
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆123Updated 4 years ago
- teler Resource Collections☆36Updated this week
- Useful resources for Zeek(https://zeek.org/) (Bro(http://bro.org/))☆32Updated 4 years ago
- Wireshark plugin to display Suricata analysis info☆93Updated 3 years ago
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 3 years ago
- PcapMonkey will provide an easy way to analyze pcap using the latest version of Suricata and Zeek.☆150Updated 11 months ago
- Meer (GPLv2) is a dedicated "spooler" for the Suricata & Sagan EVE output formats.☆23Updated 4 years ago
- Build a local copy of MITRE ATT&CK and CAPEC. Server mode for easy querying.☆32Updated this week