INACTIVE - http://mzl.la/ghe-archive - Zeek Extreme Performance Tuning
☆26Oct 10, 2019Updated 6 years ago
Alternatives and similar repositories for zept
Users that are interested in zept are comparing it to the libraries listed below
Sorting:
- A Bro package to identify connections that are bursting (lots of data and transferring quickly).☆13Oct 15, 2020Updated 5 years ago
- Plugin providing native AF_Packet support for Zeek.☆33Oct 22, 2025Updated 4 months ago
- Plugin providing AF_XDP support for Bro.☆14May 10, 2021Updated 4 years ago
- ☆24Mar 29, 2020Updated 5 years ago
- Dockerized Zeek☆12Mar 9, 2024Updated last year
- Validate if afpacket PACKET_FANOUT_HASH is working properly☆25May 19, 2022Updated 3 years ago
- Extensions for Zeek's Intelligence Framework.☆11Mar 1, 2022Updated 4 years ago
- GQUIC Protocol Analyzer for Zeek (Bro) Network Security Monitor☆80Sep 13, 2023Updated 2 years ago
- Integrate Zeek with Alienvault OTX☆25Sep 11, 2020Updated 5 years ago
- A Zeek script to generate features based on timing, volume and metadata for traffic classification.☆58Nov 8, 2020Updated 5 years ago
- A Zeek plugin to POST logs over HTTP.☆13Feb 10, 2020Updated 6 years ago
- ☆16Dec 15, 2025Updated 2 months ago
- Materials for the BSides NoVA/Charleston 2018 Bro Workshop☆14Jun 4, 2025Updated 8 months ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆33Nov 3, 2025Updated 3 months ago
- Zeek plugin to generate data on per-packet sizes and intervals☆14Apr 21, 2020Updated 5 years ago
- Full packet capture with flow cutoff, rotation, and compression☆15Sep 18, 2018Updated 7 years ago
- CyCAT.org taxonomies☆15May 22, 2021Updated 4 years ago
- ☆39Dec 4, 2023Updated 2 years ago
- Utility for parsing Bro log files into CSV or JSON format☆41Jan 12, 2023Updated 3 years ago
- subdomain_dict☆16Jun 30, 2020Updated 5 years ago
- Zeek support for Community ID flow hashing.☆37Jul 11, 2023Updated 2 years ago
- Sniffpass will alert on cleartext passwords discovered in HTTP POST requests☆17Oct 30, 2023Updated 2 years ago
- ☆14Jan 14, 2026Updated last month
- ☆16Mar 28, 2019Updated 6 years ago
- python SDK for CIFv2☆13Nov 5, 2019Updated 6 years ago
- Zeek package for detecting the Eternal* exploits and a set of SMBv1 protocol violations.☆19Aug 21, 2025Updated 6 months ago
- Firepit - STIX Columnar Storage☆18Jun 5, 2024Updated last year
- Zeek network security monitor plugin that enables parsing of the Ethernet/IP and Common Industrial Protocol standards☆46May 30, 2024Updated last year
- ☆21Oct 16, 2021Updated 4 years ago
- Extracting and analyzing URLs from Emails for phishing events☆21Oct 22, 2020Updated 5 years ago
- Meer (GPLv2) is a dedicated "spooler" for the Suricata & Sagan EVE output formats.☆23Feb 9, 2021Updated 5 years ago
- The Security Analyst’s Guide to Suricata☆61Apr 28, 2025Updated 10 months ago
- You're busted!☆27Dec 16, 2019Updated 6 years ago
- Zeek package for tracking long connections to report them before they have completed.☆31Nov 25, 2025Updated 3 months ago
- Suricata Extreme Performance Tuning guide - Mark II☆121Apr 17, 2018Updated 7 years ago
- DSL for SIMD Sorting on AVX2 & AVX512☆31Jan 11, 2019Updated 7 years ago
- Generate JSON force-directed/ node graph data from MITRE's ATTACK framework and visualize it interactively☆38Apr 19, 2025Updated 10 months ago
- OCA-wide documentation shared by all sub-projects and repositories☆33Oct 31, 2024Updated last year
- gonids is a library to parse IDS rules, with a focus primarily on Suricata rule compatibility. There is a discussion forum available that…☆192Jul 18, 2025Updated 7 months ago