trisulnsm / trisul-scripts
Ready to run scripts for network analysis
☆88Updated 3 weeks ago
Alternatives and similar repositories for trisul-scripts:
Users that are interested in trisul-scripts are comparing it to the libraries listed below
- Bro scripts to be shared with the community☆109Updated 11 years ago
- Passive DNS collection using Zeek☆182Updated last year
- Bro IDS + ELK Stack to detect and block data exfiltration☆46Updated 6 years ago
- Bro-IDS scripts☆50Updated 8 years ago
- Scripts for Bro IDS and ELK Stack☆56Updated 9 years ago
- Flow-Indexer indexes flows found in chunked log files from bro,nfdump,syslog, or pcap files☆44Updated 9 months ago
- Rule sets for Sagan☆102Updated 4 years ago
- Various Bro scripts☆96Updated 8 years ago
- CIF v3 -- the fastest way to consume threat intelligence☆183Updated last year
- Bro scripts for the ROCK platform. http://rocknsm.io☆33Updated last year
- DNSDB query scripts☆75Updated 5 years ago
- ☆75Updated 3 years ago
- ☆38Updated 6 years ago
- Bro/Zeek integration with osquery☆94Updated 4 years ago
- Centralize Management of Intrusion Detection System like Suricata Bro Ossec ...☆72Updated 5 years ago
- Wireshark plugin to display Suricata analysis info☆93Updated 3 years ago
- BGP ranking is a free software to calculate the security ranking of Internet Service Provider (ASN).☆105Updated last year
- Docker container for MISP☆96Updated 6 years ago
- Misc. Bro scripts☆63Updated 7 years ago
- How to Zeek Sysmon Logs!☆102Updated 3 years ago
- A Docker container for Moloch based on minimal Debian☆26Updated 9 years ago
- A website and framework for testing NIDS detection☆57Updated 3 years ago
- Extract files from network traffic with Zeek.☆100Updated 4 years ago
- This is a script module for Bro that encapsulates and detects activity related to the Mandiant APT1 report.☆47Updated 11 years ago
- ☆71Updated 3 years ago
- Aggregates security threats from a number of online sources, and outputs to Syslog CEF, Snort Signatures, Iptables rules, hosts.deny, etc…☆79Updated 9 years ago
- Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings☆122Updated 3 years ago
- Web service for scanning pcaps with snort☆108Updated 6 years ago
- Network Forensics Bro scripts & pcap samples☆62Updated 10 years ago
- Improvements of/over the original rule2alert☆56Updated 10 years ago