sysflow-telemetry / sf-collector
SysFlow collection probe
☆15Updated last week
Related projects ⓘ
Alternatives and complementary repositories for sf-collector
- SysFlow edge processing pipeline☆14Updated 3 months ago
- SysFlow project APIs☆15Updated 5 months ago
- SysFlow documentation and issues tracker☆45Updated last month
- This repository includes a mapping table and a reference process that allows converting between STIX 2.1 Course of Action objects that ma…☆15Updated 2 years ago
- This repository hosts community contributed Kestrel huntflows (.hf) and huntbooks (.ipynb)☆31Updated 10 months ago
- Augmentation to Machine Readable CTI☆25Updated 2 months ago
- Firepit - STIX Columnar Storage☆15Updated 5 months ago
- A set of PCAPs used to test the parsers used by Malcolm. Also, a curated list of PCAP collections I've found online.☆32Updated this week
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆37Updated 2 years ago
- OCA-wide documentation shared by all sub-projects and repositories☆33Updated 3 weeks ago
- Dockerized Zeek☆10Updated 8 months ago
- This repository hosts community contributed Kestrel analytics☆15Updated 5 months ago
- An elevated STIX representation of the MITRE ATT&CK Groups knowledge base☆23Updated 2 years ago
- A CALDERA plugin☆72Updated 3 weeks ago
- ☆37Updated 2 months ago
- Threat Detection Rules (Snort/Sigma/Yara)☆13Updated 10 months ago
- OSSEM Common Data Model☆54Updated 2 years ago
- ☆99Updated 5 months ago
- Import specific data sources into the Sigma generic and open signature format.☆77Updated 2 years ago
- A simple way of detecting multithreaded exfiltration in Zeek.☆14Updated 2 years ago
- Custom Splunk search command to reconstruct a pstree from Sysmon process creation events (EventCode 1)☆23Updated last year
- Red Canary's eBPF Sensor☆101Updated 4 months ago
- The Security Analyst’s Guide to Suricata☆52Updated 5 months ago
- A MITRE Caldera plugin☆38Updated this week
- MITRE Engage™ is a framework for conducting Denial, Deception, and Adversary Engagements.☆60Updated 7 months ago
- ☆15Updated last year
- Adversary Emulation Planner☆38Updated 4 months ago
- Zeek support for Community ID flow hashing.☆34Updated last year
- MISP-STIX-Converter - Python library to handle the conversion between MISP and STIX formats☆50Updated this week