stratosphereips / netflowlabeler
A configurable rule-based labeling tool for network flow files.
☆15Updated last year
Related projects ⓘ
Alternatives and complementary repositories for netflowlabeler
- A privacy-aware exchange module to securely and privately share your indicators☆13Updated 7 years ago
- CERTITUDE - A python package to classify malicious URLs☆20Updated 2 years ago
- Declare and keep up a rogue default-gateway in Cisco's HSRP default configuration☆17Updated 7 years ago
- Setting up a training environment for MISP☆11Updated last year
- Python CLI and module for CIRCL hash lookup☆12Updated 3 weeks ago
- A real-time Grafana dashboard using MISP ZeroMQ message queue and InfluxDB☆16Updated 8 months ago
- A Spicy protocol analyzer for WireGuard☆28Updated 4 years ago
- collect logs and alerts from 27 honeypots and send it to backed (eg peba, geba), hpfeeds, influxdb or jSON file.☆16Updated last year
- D4 core software (server and sample sensor client)☆43Updated 10 months ago
- A mapping project between tags (annotations, labels) and domain names☆11Updated 6 months ago
- BGP ranking is a free software to calculate the security ranking of Internet Service Provider (ASN)☆69Updated 4 months ago
- Network Entity Reputation Database☆33Updated 2 weeks ago
- SACTI - Securely aggregate CTI sightings and report them on MISP☆13Updated 2 years ago
- Automate the regular transfer of AIS data into a MISP Server☆6Updated 5 months ago
- Build Automated Machine Images for MISP☆28Updated last year
- The Attacker IP Prioritizer(AIP) dynamically generates resource-friendly IPv4 blocklists from Zeek network flows.☆32Updated last week
- A Passive DNS backend and collector☆31Updated 2 years ago
- Detection Rule License (DRL)☆15Updated last year
- Application and service identification rules for Suricata☆18Updated 2 years ago
- A commercial grade threat intelligence feed thats validated and updated every half hour.☆20Updated last year
- CSIRT Tooling: Best Practices in Developing, Maintaining and Distributing Open Source Tools☆16Updated 2 years ago
- nmap/ndiff based scanner with template based notification system in case of infrastructure changes☆18Updated 6 years ago
- Fast lookup server for NSRL and other hash database used in digital forensic☆41Updated 2 years ago
- This repo contains information on how to auto deploy Sysmon via GPO and Task Scheduler☆12Updated 3 years ago
- Enables Zeek to communicate with Tenzir☆11Updated last year
- Yara rules for malicious javascript files from public repositories or written by me.☆12Updated 3 years ago
- Log aggregation, analysis, alerting and correlation for Windows, Syslog and text based logs.☆24Updated 8 years ago
- Small container runtime for threat detection☆11Updated 2 years ago
- 🚀 A lightweight, fast, and comprehensive solution for traffic analysis and intrusion detection.☆20Updated this week
- Hunt for SQLite files used by various applications☆10Updated 2 weeks ago