otoriocyber / chronos
python framework to parse logs for IR
☆16Updated 3 years ago
Alternatives and similar repositories for chronos:
Users that are interested in chronos are comparing it to the libraries listed below
- OSSEM Common Data Model☆55Updated 2 years ago
- A community event for security researchers to share their favorite notebooks☆107Updated last year
- ☆17Updated 3 years ago
- The Infosec Community Definitive Guide to Jupyter Notebooks☆121Updated 4 years ago
- Posture Attribute Collection and Evaluation☆23Updated last year
- Best practices in threat intelligence☆46Updated 2 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated this week
- Salt States for Configuring the SIFT Workstation☆100Updated 2 weeks ago
- A collection of notebooks built for defensive and offensive operations.☆77Updated 4 years ago
- Elastic TIP is a python tool which automates the process of aggregating Threat Intelligence and ingesting the intelligence into a common …☆27Updated 8 months ago
- Firepit - STIX Columnar Storage☆16Updated 10 months ago
- A platform built for easy-to-use automated network traffic analysis☆59Updated 2 years ago
- Legal, procedural and policies document templates for operating MISP and information sharing communities☆38Updated 2 years ago
- Potiron - Normalize, Index and Visualize Network Capture☆85Updated 6 years ago
- defendA Data Lake. A firehose pipeline to athena providing enrichment and normalization for security events☆16Updated 2 years ago
- ☆16Updated last year
- Caldera plugin to deploy "humans" to emulate user behavior on systems☆27Updated last year
- OASIS TC Open Repository: CSAF Parser tool for parsing and checking the syntax of the Common Vulnerability Reporting Framework (CVRF) con…☆23Updated 2 years ago
- Kestrel Jupyter Notebook Kernel☆9Updated last year
- Core server components for Assemblyline 4 (Alerter, dispatcher, expiry, ingester, scaler, updater, ...)☆20Updated last week
- Converting data from services like Censys and Shodan to a common data model☆49Updated 7 months ago
- Rapid cybersecurity toolkit based on Elastic in Docker. Designed to quickly build elastic-based environments to analyze and execute threa…☆18Updated 5 years ago
- CyCAT.org API back-end server including crawlers☆29Updated 2 years ago
- Actionable analytics designed to combat threats based on MITRE's ATT&CK.☆22Updated 5 years ago
- Zeek package for tracking long connections to report them before they have completed.☆30Updated 2 months ago
- Import specific data sources into the Sigma generic and open signature format.☆78Updated 2 years ago
- Packer.io Scripts to build the SIFT VM(s)☆11Updated 4 years ago
- A Python implementation of the Community ID flow hashing standard☆23Updated last year
- An ELK environment containing interesting security datasets.☆136Updated 4 years ago
- Vuls Beater for Elasticsearch - connecting vuls☆17Updated 4 years ago