nccgroup / Splunking-CrimeLinks
Splunking Crime using Splunk Machine Learning Toolkit
☆11Updated 7 years ago
Alternatives and similar repositories for Splunking-Crime
Users that are interested in Splunking-Crime are comparing it to the libraries listed below
Sorting:
- CARET - A tool for viewing cyber analytic relationships☆55Updated 6 years ago
- A collection of notebooks built for defensive and offensive operations.☆77Updated 5 years ago
- Client API to query any Passive DNS implementation following the Passive DNS - Common Output Format.☆81Updated last month
- Splunk scripted input for opening a backconnect shell on a remote forwarder☆45Updated 5 years ago
- Proof of concept implementation of a cyber threat intelligence and incident handling platform☆11Updated 2 years ago
- This project contains code for comparing or ranking APT capabilities and operational capacity. The metrics are meant to quantify, rank, o…☆35Updated 6 years ago
- Bro PCAP Processing and Tagging API☆28Updated 8 years ago
- stoQ Public Plugins☆71Updated 2 years ago
- Network Forensics Bro scripts & pcap samples☆63Updated 11 years ago
- Bro IDS + ELK Stack to detect and block data exfiltration☆46Updated 7 years ago
- OpenDNS Graph Miner☆45Updated 8 years ago
- Python scripts to download, parse, and enrich scans.io study data and load into Splunk for research, threat intelligence gathering, and s…☆19Updated last month
- ☆35Updated 4 years ago
- Open-source framework to detect outliers in Elasticsearch events☆208Updated 2 years ago
- Clearcut is a tool that uses machine learning to help you focus on the log entries that really need manual review☆197Updated 9 years ago
- Repository of all the sites related to infosec IP/Domain/Hash/SSL/etc OSINT and eventually will include more.☆70Updated 3 months ago
- Splunk Alert Manager with advanced reporting on alerts, workflows (modify assignee, status, severity) and auto-resolve features☆83Updated 3 years ago
- A Python library to help with some common threat hunting data analysis operations☆143Updated 2 years ago
- How to Zeek Sysmon Logs!☆103Updated 3 years ago
- Workbench: A scalable python framework for security research and development teams.☆92Updated 6 years ago
- Normalizer for honeypot data.☆11Updated 2 years ago
- Ragpicker is a Plugin based malware crawler with pre-analysis and reporting functionalities. Use this tool if you are testing antivirus p…☆94Updated 10 years ago
- Python abstract API for PassiveTotal services in the form of libraries and command line utilities.☆86Updated 2 years ago
- ☆21Updated 5 years ago
- Detecting Lateral Movement with Machine Learning☆139Updated 8 years ago
- Assimilate is a series of scripts for using the Naïve Bayes algorithm to find potential malicious activity in HTTP headers☆92Updated 8 years ago
- ☆36Updated 5 years ago
- An anomaly-based intrusion detection system.☆85Updated 3 years ago
- shell script to create an image and perform initial examination on a drive☆15Updated 5 years ago
- ☆10Updated 5 years ago