secureworks / dalton
Suricata, Snort and Zeek IDS rule and pcap testing system
☆452Updated this week
Related projects ⓘ
Alternatives and complementary repositories for dalton
- a network packet capture compiler☆194Updated 2 years ago
- Scirius is a web application for Suricata ruleset management and threat hunting.☆635Updated last week
- The tool for updating your Suricata rules.☆255Updated 4 months ago
- Tool to extract indicators of compromise from security reports in PDF format☆429Updated last year
- Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search☆431Updated last week
- Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark☆423Updated 10 months ago
- idstools: Snort and Suricata Rule and Event Utilities in Python (Including a Rule Update Tool)☆276Updated last year
- PCAP Samples for Different Post Exploitation Techniques☆344Updated 3 years ago
- Mirror of https://github.com/zeek/zeek☆167Updated last year
- Suricata Extreme Performance Tuning guide☆204Updated 6 years ago
- Mapping the MITRE ATT&CK Matrix with Osquery☆776Updated last year
- A set of Zeek scripts to detect ATT&CK techniques.☆565Updated 4 months ago
- Defanged Indicator of Compromise (IOC) Extractor.☆506Updated 2 months ago
- ☆1,051Updated 5 years ago
- Automatic Yara Rule Generation☆332Updated 8 years ago
- IntelMQ is a solution for IT security teams for collecting and processing security feeds using a message queuing protocol.☆976Updated 2 weeks ago
- Suricata rules for network anomaly detection☆153Updated 2 months ago
- This repository will hold PCAP IOC data related with known malware samples (owner: Bryant Smith)☆98Updated 3 years ago
- Security event correlation engine for ELK stack☆434Updated 4 months ago
- Elemental - An ATT&CK Threat Library☆314Updated last year
- Detecting ATT&CK techniques & tactics for Linux☆256Updated 4 years ago
- DPS' Lightweight Investigation Notebook☆423Updated 10 months ago
- Extract and aggregate threat intelligence.☆831Updated 9 months ago
- Praetorian's public release of our Metasploit automation of MITRE ATT&CK™ TTPs☆718Updated 4 years ago
- ☆506Updated 3 years ago
- The Python SDK for AlienVault OTX☆358Updated 6 months ago
- Cuckoo Sandbox Dockerfile☆322Updated 4 years ago
- The GOSINT framework is a project used for collecting, processing, and exporting high quality indicators of compromise (IOCs).☆537Updated last year
- ☆168Updated 3 years ago
- An analytical framework for network traffic and behavioral analytics☆449Updated last year