trisulnsm / apps
Plugin packages that provide custom visualizations and analytics capabilities to Trisul Network Analytics.
☆16Updated this week
Alternatives and similar repositories for apps:
Users that are interested in apps are comparing it to the libraries listed below
- GQUIC Protocol Analyzer for Zeek (Bro) Network Security Monitor☆75Updated last year
- Python framework for manipulating bulk WHOIS data from RIRs☆20Updated 2 years ago
- Golang based web service to scan files with yara rules☆27Updated 7 years ago
- ssh key exchange layer for scapy☆13Updated 10 years ago
- A dsniff project using bro☆10Updated 9 years ago
- Network timing evaluation used to detect beacons, works with argus flow as the source☆19Updated 8 years ago
- A tool to generate log messages related to interfaces, neighbor cache (ARP,NDP), IP address, routing, FIB rules, traffic control.☆32Updated 3 months ago
- Bro analyzer that detects Google's QUIC protocol☆10Updated 3 years ago
- A native and unofficial implementation of p0f3 in Python with extra analysis features: It's p0f3+!☆25Updated 2 years ago
- Some of the presentations given by me☆17Updated 2 months ago
- Automatically enumerate and fingerprint SD-WAN nodes on the internet☆50Updated 3 years ago
- A mysql honeypot, still very very early stage☆21Updated 12 years ago
- JA3 TLS Fingerprint database☆75Updated 5 years ago
- Suricata rule and intel index☆30Updated last month
- QUICk - a go library based on gopacket for analyzing QUIC CHLO messages☆22Updated 4 years ago
- alertflex controller☆10Updated last year
- Growing collection of Spicy-based protocol and file analyzers for Zeek☆31Updated 4 months ago
- Plugin providing AF_XDP support for Bro.☆14Updated 3 years ago
- Prototype system to monitor BGP routes and alert when anomalies are identified☆14Updated 6 years ago
- A Passive DNS backend and collector☆31Updated 2 years ago
- encoding format, library, and utilities for passive DNS data☆26Updated 10 months ago
- Mirror network traffic from one interface to another on Windows☆25Updated 4 years ago
- Python library for image hashing and deduplication☆11Updated 8 years ago
- The ModSecurity Pcap Connector☆26Updated 9 years ago
- This is the C version of the StratosphereLinuxIPS. It is mainly used for integration with Snort and other IDSs.☆12Updated 7 years ago
- cve-search is a tool to import CVE (Common Vulnerabilities and Exposures) and CPE (Common Platform Enumeration) into a MongoDB to facilit…☆25Updated 7 years ago
- Signature-free approach library to detect injection and commanding attacks☆86Updated 3 years ago
- Scan blob files for sensitive content☆11Updated 2 years ago
- Useful resources for Zeek(https://zeek.org/) (Bro(http://bro.org/))☆32Updated 4 years ago
- IDS Utility Belt For Automating/Testing Various Things☆30Updated 4 years ago