salesforce / GQUIC_Protocol_Analyzer
GQUIC Protocol Analyzer for Zeek (Bro) Network Security Monitor
☆75Updated last year
Related projects: ⓘ
- Plugin for Zeek/Bro which provides http2 decoder/analyzer☆30Updated 3 months ago
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆124Updated 3 years ago
- Wireshark plugin to display Suricata analysis info☆91Updated 2 years ago
- BGP ranking is a free software to calculate the security ranking of Internet Service Provider (ASN)☆68Updated 2 months ago
- JA3 TLS Fingerprint database☆72Updated 4 years ago
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆32Updated this week
- INACTIVE - http://mzl.la/ghe-archive - Zeek Extreme Performance Tuning☆25Updated 4 years ago
- Ready to run scripts for network analysis☆83Updated 3 weeks ago
- A wireshark/tshark plugin for the JA3 TLS Client Fingerprinting Algorithm☆56Updated last year
- Zeek support for Community ID flow hashing.☆32Updated last year
- Plugin providing AF_XDP support for Bro.☆14Updated 3 years ago
- How to Zeek Sysmon Logs!☆100Updated 2 years ago
- IP ASN History to find ASN announcing an IP and the closest prefix announcing it at a specific date☆91Updated 2 months ago
- Python tool for converting from joy format to JA3 format SSL/TLS hashes☆11Updated 4 years ago
- Remote Desktop Client Fingerprint script for Zeek. Based off of https://github.com/0x4D31/fatt☆36Updated last year
- Bro IDS + ELK Stack to detect and block data exfiltration☆46Updated 5 years ago
- Mapping NSM rules to MITRE ATT&CK☆68Updated 4 years ago
- Suricata Verification Tests - Testing Suricata Output☆99Updated this week
- fast, extensible, versatile event router for Suricata's EVE-JSON format☆50Updated 2 months ago
- This repository will hold PCAP IOC data related with known malware samples (owner: Bryant Smith)☆98Updated 3 years ago
- Plugin providing native AF_Packet support for Zeek.☆33Updated 5 months ago
- ☆52Updated this week
- Bro/Zeek integration with osquery☆95Updated 3 years ago
- aka GENESIDS: Reads and parses rules using a "snort like" syntax and generates and sends packets that trigger events in signature based I…☆22Updated 5 years ago
- A Spicy protocol analyzer for WireGuard☆27Updated 4 years ago
- ☆35Updated 8 months ago
- Sighting DB is designed to scale writing and reading a count of attributes, tracking when if was first and last seen☆16Updated 5 months ago
- Zeek plugin to generate data on per-packet sizes and intervals☆13Updated 4 years ago
- Potiron - Normalize, Index and Visualize Network Capture☆83Updated 5 years ago
- Accurate, modular, scalable PCAP manipulation tool written in Go.☆85Updated 4 months ago