mole-ids / mole
Yara powered NIDS with high speed packet capture powered by PF_RING
☆69Updated 11 months ago
Alternatives and similar repositories for mole:
Users that are interested in mole are comparing it to the libraries listed below
- Go implementation of the Community ID flow hashing standard☆20Updated last month
- How to Zeek Sysmon Logs!☆101Updated 3 years ago
- simple YARA-based IOC scanner☆168Updated 2 months ago
- APIs for generating STIX 2.1 and TAXII 2.1 messages with Go (Golang)☆53Updated 4 months ago
- Mapping NSM rules to MITRE ATT&CK☆71Updated 4 years ago
- Zeek IDS Dockerfile☆101Updated 2 years ago
- go-atomicredteam is a Golang application to execute tests as defined in the atomics folder of Red Canary's Atomic Red Team project (https…☆49Updated 2 years ago
- Freki is a tool to manipulate packets in usermode using NFQUEUE and golang.☆58Updated 2 years ago
- Useful resources for Zeek(https://zeek.org/) (Bro(http://bro.org/))☆31Updated 5 years ago
- Accurate, modular, scalable PCAP manipulation tool written in Go.☆87Updated 11 months ago
- A Go implementation and parser for Sigma rules.☆86Updated 7 months ago
- Provide a shell like interface by utilizing osquery's distributed API☆81Updated 4 years ago
- Rule sets for Sagan