sshahriyar / totalads
Total Anomaly Detection System for software logs and traces
☆9Updated 8 years ago
Related projects ⓘ
Alternatives and complementary repositories for totalads
- Mine patterns from logs☆27Updated 7 years ago
- Network timing evaluation used to detect beacons, works with argus flow as the source☆19Updated 8 years ago
- Random scripts for log mining, intel gathering, network querying, and other incident response-ish activities☆16Updated 2 years ago
- User anomaly detector based on logs generated by Osquery framework and machine learning to process those logs.☆33Updated 7 years ago
- Simple parser for Splunk Processing Language (SPL) written in Python.☆35Updated 6 years ago
- Query.AI plugin for Kibana☆13Updated 5 years ago
- The Auditd Framework logs and applies security policy to linux auditd data☆15Updated 6 years ago
- ☆15Updated 6 years ago
- Download a demo version of Open Network Insight, which can be run standalone on a windows laptop using Winpython https://sourceforge.net/…☆9Updated 7 years ago
- Debian and Red Hat packaging for SIE DNS sensor☆15Updated last year
- Generates visualizations from the output of flow tools such as SiLK.☆35Updated 7 years ago
- Utility for parsing Bro log files into CSV or JSON format☆41Updated last year
- Classifier to separate legitimate domains from those generated by a domain generating algorithm (DGA).☆42Updated 8 years ago
- IntelMQ command line tool to process events and send out email notifications.☆9Updated 2 months ago
- A Zeek package that detects Zoom logins and meeting joins☆11Updated 4 years ago
- Getting Started with ELK☆50Updated 8 years ago
- Exporting MISP event attributes to yara rules usable with Thor apt scanner☆24Updated 7 years ago
- Python libary to normalize Yara signatures☆19Updated 4 years ago
- Hogzilla is an Intrusion Detection System (IDS) supported by Snort, Apache Spark, HBase and libnDPI, which provides Network Anomaly Detec…☆28Updated 6 years ago
- Bro Intel Feed Linter☆26Updated 5 years ago
- A tool to convert MISP XML files (events and attributes) into graphs☆20Updated 7 years ago
- CybOX Schemas and Schema Development☆42Updated 7 years ago
- Zeek script library for getting the effective TLD of a domain.☆13Updated 7 months ago
- [ABANDONED] A Docker container running Suricata and the ELK stack.☆22Updated 8 years ago
- Collection of data sources that can be used to provide context to security events☆25Updated 9 years ago
- ☆9Updated 6 years ago
- automatic enumeration and maintenance of Suricata monitoring interfaces☆11Updated 4 years ago
- Implementation of Context-Graph algorithms for graph enrichment and querying.☆24Updated 9 years ago