pentestfail / Bro-KEN
An engine for Bro IDS using Kibana, ElasticSearch, & NXLOG (KEN)
☆10Updated 9 years ago
Alternatives and similar repositories for Bro-KEN:
Users that are interested in Bro-KEN are comparing it to the libraries listed below
- Cyber Defence Monitoring Course Suite :: Suricata, Bro, Moloch☆61Updated 7 years ago
- Simple block lists hub for PAN-OS DBL feature☆35Updated 6 years ago
- Check_ioc is a script to check for various, selectable indicators of compromise on Windows systems via PowerShell and Event Logs. It was …☆76Updated 7 years ago
- PowerShell Module for automating Tenable Nessus Vulnerability Scanner.☆88Updated 2 years ago
- vagrant multi-machine: Moloch, Bro,Suricata,ElasticSearch,Kibana☆41Updated 10 years ago
- Maps process creation logged by Sysmon uses Google Org Chart API☆24Updated 8 years ago
- This module is used to report phishing URLs to their WHOIS/RDAP abuse contact information.☆42Updated 7 years ago
- ☆24Updated 4 years ago
- ☆36Updated 4 years ago
- Push "BAD" IPs/Networks into QRadar's "Remote Networks", tag them properly, and use them!☆18Updated 11 years ago
- Dockerfiles for NSM tools☆84Updated 7 years ago
- ☆38Updated 6 years ago
- This is a repository from Adam Swan and I's presentation on Windows Logs Zero 2 Hero.☆21Updated 6 years ago
- Cyber Analytics Platform and Examination System (CAPES) Project Page☆60Updated 5 years ago
- Queries to parse sysmon event log file with microsoft logparser☆56Updated 9 years ago
- Repository with logstash, elasticsearch and kibana configs. Palo Alto, Juniper, BlueCoat, etc.☆18Updated 7 months ago
- Miscellaneous PowerShell scripts☆58Updated 5 years ago
- Bro/Zeek integration with osquery☆94Updated 4 years ago
- Logstash configuration files for analyzing various types of logs☆25Updated 8 years ago
- Random scripts posted for my blog at http://aka.ms/goateepfe☆25Updated 7 years ago
- MineMeld nodes for MISP☆18Updated 11 months ago
- Bit9 Platform☆20Updated 7 years ago
- Ansible playbook to install Malware Information Sharing Platform (MISP)☆17Updated 9 years ago
- This is a script module for Bro that encapsulates and detects activity related to the Mandiant APT1 report.☆47Updated 10 years ago
- Bro script package to create JSON formatted logs to stream into data analysis systems.☆28Updated last year
- Ansible playbook for installing MineMeld on Linux☆48Updated 3 years ago