otoriocyber / chronos
python framework to parse logs for IR
☆16Updated 3 years ago
Alternatives and similar repositories for chronos:
Users that are interested in chronos are comparing it to the libraries listed below
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated last month
- Elastic TIP is a python tool which automates the process of aggregating Threat Intelligence and ingesting the intelligence into a common …☆27Updated 7 months ago
- Analyse a forensic target (such as a directory) to find and report files found and not found from CIRCL hashlookup public service - https…☆126Updated last year
- A community event for security researchers to share their favorite notebooks☆107Updated last year
- Potiron - Normalize, Index and Visualize Network Capture☆85Updated 6 years ago
- Core server components for Assemblyline 4 (Alerter, dispatcher, expiry, ingester, scaler, updater, ...)☆20Updated this week
- The Infosec Community Definitive Guide to Jupyter Notebooks☆121Updated 4 years ago
- Best practices in threat intelligence☆46Updated 2 years ago
- Tool for managing Zeek deployments.☆54Updated last week
- OSSEM Common Data Model☆55Updated 2 years ago
- ☆17Updated 3 years ago
- A collection of notebooks built for defensive and offensive operations.☆77Updated 4 years ago
- Firepit - STIX Columnar Storage☆16Updated 9 months ago
- A packet capture visualizer for industrial control networks.☆53Updated last year
- Posture Attribute Collection and Evaluation☆23Updated last year
- Base components for Assemblyline 4 (Datastore, ODM, Filestore, Remote Datatypes, utils function, etc...)☆69Updated this week
- The NAVV (Network Architecture Verification and Validation) tool creates a spreadsheet for network traffic analysis from PCAP data and Ze…☆30Updated 9 months ago
- Yara-Endpoint is a tool useful for incident response as well as anti-malware enpoint base on Yara signatures.☆106Updated 7 years ago
- Crucible is a modular framework for creating, deploying, and managing virtual environments to support training, education, and exercises.☆33Updated this week
- Cisco Orbital - Osquery queries by Talos☆130Updated 7 months ago
- Packer.io Scripts to build the SIFT VM(s)☆11Updated 4 years ago
- A Spicy protocol analyzer for WireGuard☆29Updated 4 years ago
- A python script to acquire multiple aws ec2 instances in a forensically sound-ish way☆38Updated 3 years ago
- Converting data from services like Censys and Shodan to a common data model☆49Updated 6 months ago
- Rapid cybersecurity toolkit based on Elastic in Docker. Designed to quickly build elastic-based environments to analyze and execute threa…☆18Updated 4 years ago
- Salt States for Configuring the SIFT Workstation☆100Updated last week
- Contains log samples and configuration files for the Tactical Data Handling at Scale with Logstash course☆11Updated 5 years ago
- 1-Click push forensics evidence to the cloud☆142Updated 9 months ago
- A platform built for easy-to-use automated network traffic analysis☆59Updated 2 years ago
- Osquery Resources☆60Updated 5 years ago