theY4Kman / suricata-prettifierLinks
Command-line tool to format and syntax highlight Suricata rules
β13Updated 5 years ago
Alternatives and similar repositories for suricata-prettifier
Users that are interested in suricata-prettifier are comparing it to the libraries listed below
Sorting:
- π΄ The STIX2 Pattern expression parser for humansβ26Updated 6 years ago
- snake-core - the real snakeβ15Updated 2 years ago
- Parse Suricata rulesβ13Updated 2 years ago
- A python script to shift the timestamp on syslog data. Useful for forensicators combating time skew.β21Updated 3 years ago
- YETI (Your Everyday Threat Intelligence) Integration to Elastic Stackβ16Updated 4 years ago
- pollen - A command-line tool for interacting with TheHiveβ35Updated 6 years ago
- Pythonic way to work with the warning lists defined there: https://github.com/MISP/misp-warninglistsβ33Updated this week
- Find abuse contacts for observablesβ70Updated 2 years ago
- A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout forβ¦β37Updated 3 years ago
- Elasticsearch/Kibana environment and log data for Sigma workshopβ27Updated 5 years ago
- Client API to query any Passive DNS implementation following the Passive DNS - Common Output Format.β82Updated 7 months ago
- fqdn_parser (Fully Qualified Domain Name Parser) is a library for parsing FQDNs into their component parts, as well as providing additionβ¦β27Updated last year
- Fang and defang indicators of compromise. You can test this project in a GUI here: http://ioc-fanger.hightower.space .β65Updated 2 years ago
- Serverless, real-time, ClamAV+Yara scanning for your S3 Bucketsβ32Updated 3 months ago
- Incident Response Network Toolsβ24Updated 4 years ago
- Automatic detection engineering technical state complianceβ55Updated last year
- Modular command-line threat hunting tool & framework.β17Updated 5 years ago
- Fast lookup server for NSRL and other hash database used in digital forensicβ45Updated 3 years ago
- Wireshark plugin to display Suricata analysis infoβ95Updated 3 years ago
- Zeek package to detect Zerologonβ11Updated 3 years ago
- β18Updated 7 years ago
- D4 core software (server and sample sensor client)β42Updated last year
- A Python implementation of the Community ID flow hashing standardβ23Updated last year
- Zeek package for tracking long connections to report them before they have completed.β31Updated 3 months ago
- Extract indicators of compromise from text, including "escaped" ones.β162Updated 5 years ago
- Check IOC provided by a MISP instance on Suricata eventsβ18Updated 6 years ago
- Workflows for Shuffleβ23Updated 2 years ago
- pyJARM is a library for doing JARM fingerprinting using pythonβ50Updated 6 months ago
- β35Updated 4 years ago
- setup zeek, previously Bro IDSβ18Updated this week