☆15Aug 11, 2019Updated 6 years ago
Alternatives and similar repositories for bro-elk-IDS
Users that are interested in bro-elk-IDS are comparing it to the libraries listed below
Sorting:
- Logstash configuration files for analyzing various types of logs☆25Dec 9, 2016Updated 9 years ago
- A web interface for interacting with your Bro IDS logs.☆86Jun 10, 2021Updated 4 years ago
- ssh key exchange layer for scapy☆13Oct 27, 2014Updated 11 years ago
- JoeSandbox-Bro is a simple bro script which extracts files from your internet connection and analyzes them automatically on Joe Sandbox☆44Jun 6, 2019Updated 6 years ago
- Docker files for building Zeek.☆89Oct 12, 2023Updated 2 years ago
- Contributed Bro Scripts☆30May 28, 2014Updated 11 years ago
- Network Forensics Bro scripts & pcap samples☆63Mar 11, 2014Updated 11 years ago
- This is a script module for Bro that encapsulates and detects activity related to the Mandiant APT1 report.☆51Feb 11, 2014Updated 12 years ago
- A collection of Bro scripts I've written☆41Jun 5, 2015Updated 10 years ago
- Splunk App to assist Sysmon Threat Hunting☆38Mar 7, 2017Updated 9 years ago
- ELK configuration files for Forensic Analysts and Incident Handlers (unmaintained)☆179Jul 10, 2019Updated 6 years ago
- Fix for the CVE-2021-36934☆10Oct 15, 2021Updated 4 years ago
- Create a netfilter queue and display packets passing through. Can also save those packets to a pcap file.☆13Dec 3, 2011Updated 14 years ago
- Baidu 100G Chasiss Switch hardware spec☆12Sep 20, 2017Updated 8 years ago
- How to create VMware vagrant box☆11May 10, 2020Updated 5 years ago
- Scripts that cover the basics of interacting with the Threat Grid API☆11Jan 21, 2020Updated 6 years ago
- Threat Response API Module☆10Oct 4, 2023Updated 2 years ago
- PowerShell tool to enumerate existing exclusions in Windows Defender as low privileged user☆11Oct 14, 2024Updated last year
- This is a python script that can be run on each Splunk Indexer for the purpose of exporting historical bucket data (raw events + metadata…☆12Jan 31, 2024Updated 2 years ago
- MongoDB Login Brute Forcer☆11Jun 22, 2014Updated 11 years ago
- ☆11Jun 9, 2020Updated 5 years ago
- The evolution of NxRansomware☆11Jun 14, 2019Updated 6 years ago
- Port of Mandiant ShellcodeHashes plugin from IDA to BinaryNinja☆11Jul 24, 2024Updated last year
- NDISPktScan is a plugin for the Volatility Framework. It parses the Ethernet packets stored by ndis.sys in Windows kernel space memory.☆12Oct 23, 2015Updated 10 years ago
- Extra cmdlets to help with quering security related information from Azure☆14Sep 16, 2024Updated last year
- Lambda handler for Yelp's ElastAlert☆14Feb 1, 2019Updated 7 years ago
- Quantum Insert Backdoor POC☆11May 21, 2017Updated 8 years ago
- Silent Cleanup UAC Bypass POC☆11Dec 15, 2019Updated 6 years ago
- Auxiliary scripts for Incident Response with ELK☆11Oct 7, 2015Updated 10 years ago
- ☆10Nov 21, 2023Updated 2 years ago
- This directory contains random scripts from threat hunting or malware research☆11Feb 15, 2018Updated 8 years ago
- Repo for the OWASP Quick Start Guide☆10Jan 13, 2015Updated 11 years ago
- Android Phone FireWall , it could help you to filter the boring Message and unknow Call.☆13May 22, 2013Updated 12 years ago
- 🗄️ collection of data for runescape classic☆12Dec 15, 2020Updated 5 years ago
- more extensions for https://rpcx.io☆10Apr 11, 2021Updated 4 years ago
- Logged PS Remote Command Wrapper for Blue Team Forensics/IR☆11Apr 12, 2018Updated 7 years ago
- Sysmon Tools for PowerShell☆12Aug 17, 2018Updated 7 years ago
- An extension to the standard python 2.x smtpd library implementing implicit/explicit SSL/TLS/STARTTLS☆11Nov 29, 2018Updated 7 years ago
- Spider or repeater to find all links.☆10Feb 7, 2021Updated 5 years ago