openargus / argus
Argus Sensor
☆57Updated last month
Alternatives and similar repositories for argus:
Users that are interested in argus are comparing it to the libraries listed below
- Argus clients program repo☆19Updated last week
- Open source endpoint agent providing host information to Zeek. [v2]☆72Updated 2 months ago
- Suricata Verification Tests - Testing Suricata Output☆104Updated this week
- Suricata rules for network anomaly detection☆154Updated last month
- PcapMonkey will provide an easy way to analyze pcap using the latest version of Suricata and Zeek.☆147Updated 10 months ago
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆173Updated 3 months ago
- Sagan is a multi-threads, high performance log analysis engine. At it's core, Sagan similar to Suricata/Snort but with logs rather th…☆160Updated 2 months ago
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆66Updated this week
- Suricata Extreme Performance Tuning guide - Mark II☆115Updated 6 years ago
- A completely automated anomaly detector Zeek network flows files (conn.log).☆75Updated 5 months ago
- Cisco Orbital - Osquery queries by Talos☆127Updated 4 months ago
- Zeek Training Materials/Products☆37Updated 3 months ago
- Plugin providing native AF_Packet support for Zeek.☆34Updated 9 months ago
- The tool for updating your Suricata rules.☆262Updated last month
- The Security Analyst’s Guide to Suricata☆53Updated 7 months ago
- Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)☆78Updated 3 months ago
- DynamiteNSM is a free Network Security Monitor developed by Dynamite Analytics to enable network visibility and advanced cyber threat det…☆167Updated last year
- Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs an…☆373Updated last week
- Industrial Control Systems Network Protocol Parsers☆160Updated last week
- Zeek Extension to Collect Metadata for Profiling of Endpoints and Proxies☆27Updated 10 months ago
- Collection of various open-source an commercial rulesets for NIDS (especially for Suricata and Snort)☆23Updated last year
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆37Updated 2 years ago
- Zeek-Formatted Threat Intelligence Feeds☆347Updated this week
- Red Canary's eBPF Sensor☆101Updated 6 months ago
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆31Updated 4 months ago
- Zeek IDS Dockerfile☆100Updated 2 years ago
- Accurate, modular, scalable PCAP manipulation tool written in Go.☆86Updated 8 months ago
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆123Updated 4 years ago
- fast, extensible, versatile event router for Suricata's EVE-JSON format☆51Updated 6 months ago