sysflow-telemetry / sf-apis
SysFlow project APIs
☆15Updated 7 months ago
Alternatives and similar repositories for sf-apis:
Users that are interested in sf-apis are comparing it to the libraries listed below
- Mapping NSM rules to MITRE ATT&CK☆68Updated 4 years ago
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆123Updated 4 years ago
- Plugin providing native AF_Packet support for Zeek.☆34Updated 9 months ago
- Zeek support for Community ID flow hashing.☆35Updated last year
- A completely automated anomaly detector Zeek network flows files (conn.log).☆75Updated 5 months ago
- SysFlow collection probe☆16Updated 3 weeks ago
- This repository will hold PCAP IOC data related with known malware samples (owner: Bryant Smith)☆100Updated 3 years ago
- Client API to query any Passive DNS implementation following the Passive DNS - Common Output Format.☆76Updated this week
- ☆159Updated 4 years ago
- Wireshark plugin to display Suricata analysis info☆93Updated 3 years ago
- A lightweight tool to load Windows Event Log evtx files into Elasticsearch.☆115Updated 4 years ago
- Bro/Zeek integration with osquery☆94Updated 4 years ago
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆174Updated 4 months ago
- zeek-scripts☆43Updated 6 years ago
- Extract files from network traffic with Zeek.☆100Updated 4 years ago
- CIFv3 DeploymentKit☆63Updated 4 years ago
- 🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.☆261Updated last year
- Place for resources used during the Mordor Detection hackathon event featuring APT29 ATT&CK evals datasets☆133Updated 4 years ago
- OASIS TC Open Repository: GitHub Pages site for STIX and TAXII☆97Updated 3 months ago
- Rule sets for Sagan☆102Updated 4 years ago
- This script scans the files extracted by Zeek with YARA rules located on the rules folder on a Linux based Zeek sensor, if there is a mat…☆61Updated last year
- An easy ATT&CK-based Sysmon hunting tool, showing in Blackhat USA 2019 Arsenal☆201Updated 2 years ago
- SysFlow documentation and issues tracker☆46Updated 4 months ago
- Download pcap files from http://www.malware-traffic-analysis.net/☆74Updated 7 years ago
- ☆35Updated last year
- Apache Metron☆59Updated 4 years ago
- ☆218Updated last year
- Definition, description and relationship types of MISP objects☆94Updated last week
- Python tool for converting from joy format to JA3 format SSL/TLS hashes☆11Updated 4 years ago
- A website and framework for testing NIDS detection☆56Updated 3 years ago