thomaspatzke / EQUEL
An Elasticsearch QUEry Language
☆56Updated 7 years ago
Alternatives and similar repositories for EQUEL:
Users that are interested in EQUEL are comparing it to the libraries listed below
- ☆75Updated 3 years ago
- ☆28Updated 8 years ago
- integrating bro into yara☆33Updated 10 years ago
- This is a repository from Adam Swan and I's presentation on Windows Logs Zero 2 Hero.☆22Updated 7 years ago
- Bro/Zeek integration with osquery☆94Updated 4 years ago
- Python interface to the CRITs API☆22Updated 7 years ago
- Python tool and library to help analyze files during malware triage and analysis.☆78Updated 4 years ago
- IDS Utility Belt For Automating/Testing Various Things☆30Updated 4 years ago
- BTG's purpose is to make fast and efficient search on IOC☆70Updated 6 years ago
- Automated install scripts for Cuckoo sandbox☆37Updated 7 years ago
- Command-line Interface for Binar.ly☆37Updated 8 years ago
- Honeypot log processor to create OTX Pulse entries☆29Updated last year
- Malware/IOC ingestion and processing engine☆104Updated 6 years ago
- ☆19Updated 6 years ago
- A Windows Event Processing Utility☆46Updated 7 years ago
- Some IR notes☆73Updated 8 years ago
- Quick tool for using Hybrid Analysis API on command line..☆17Updated 7 years ago
- Bro-IDS scripts☆50Updated 8 years ago
- Sandbox feature upgrade with the help of wrapped samples☆76Updated 6 years ago
- My Yara Rules Collection☆52Updated 9 years ago
- Scripts for Bro IDS and ELK Stack☆56Updated 9 years ago
- ☆22Updated 7 years ago
- ☆33Updated 4 years ago
- This is a script module for Bro that encapsulates and detects activity related to the Mandiant APT1 report.☆47Updated 11 years ago
- Ragpicker is a Plugin based malware crawler with pre-analysis and reporting functionalities. Use this tool if you are testing antivirus p…☆94Updated 9 years ago
- Manage VT Alerts☆62Updated 8 years ago
- This project contains code for comparing or ranking APT capabilities and operational capacity. The metrics are meant to quantify, rank, o…☆35Updated 6 years ago
- Python scripts to parse scans.io ssl data and ingest into elasticsearch for searching☆33Updated 8 years ago
- SANS Hunting on the Cheap☆35Updated 8 years ago
- Sysmon config for both Windows and Linux Devices. Windows one is a bit dated☆55Updated 7 months ago