zeek / zeek-osqueryView external linksLinks
Bro/Zeek integration with osquery
☆94Nov 2, 2020Updated 5 years ago
Alternatives and similar repositories for zeek-osquery
Users that are interested in zeek-osquery are comparing it to the libraries listed below
Sorting:
- Extensions for Zeek's Intelligence Framework.☆11Mar 1, 2022Updated 3 years ago
- Experimental Bro scripts with good prospects for the official bro-scripts repository.☆20Nov 2, 2017Updated 8 years ago
- Bro Intel Feed Linter☆26Aug 30, 2019Updated 6 years ago
- A collection of Bro scripts I've written☆41Jun 5, 2015Updated 10 years ago
- Bro integration with osquery☆15Mar 24, 2023Updated 2 years ago
- How to Zeek Sysmon Logs!☆103Feb 12, 2022Updated 4 years ago
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆124Nov 19, 2020Updated 5 years ago
- Various Bro scripts☆96Jul 8, 2016Updated 9 years ago
- A collection of bro_scripts and signatures☆27Jun 26, 2019Updated 6 years ago
- Bro Snippets☆21Nov 7, 2014Updated 11 years ago
- Bro-IDS scripts☆50Sep 12, 2016Updated 9 years ago
- Bro PCAP Processing and Tagging API☆28Nov 9, 2017Updated 8 years ago
- The default package source of the Zeek Package Manager. Wrote a package? See the README for how to get it included.☆144Jan 29, 2026Updated 2 weeks ago
- scan-detection policies for bro☆16Jan 16, 2025Updated last year
- Zeek plugin to generate data on per-packet sizes and intervals☆14Apr 21, 2020Updated 5 years ago
- Using osquery for Mass Incident Detection & Response☆19Jun 25, 2016Updated 9 years ago
- Utilities and scripts for bro-ids☆23Jan 6, 2014Updated 12 years ago
- dankAlerts is powered by Sysmon and Memes. Would you notice if a suspicious process was recorded in the event log?☆18Jun 24, 2020Updated 5 years ago
- ☆72Nov 17, 2021Updated 4 years ago
- Plugin for Zeek/Bro which provides http2 decoder/analyzer☆30Jun 11, 2024Updated last year
- Script for generating Bro intel files from pdf or html reports☆77Dec 7, 2015Updated 10 years ago
- Bro scripts to monitor for new hosts within a subnet range that aren't whitelisted/vetted.☆13Jun 28, 2013Updated 12 years ago
- Zeek package to generate a SMB client fingerprint☆27May 5, 2020Updated 5 years ago
- Validate if afpacket PACKET_FANOUT_HASH is working properly☆25May 19, 2022Updated 3 years ago
- ☆14Jan 14, 2026Updated last month
- Bro scripts written by CrowdStrike Services☆148May 3, 2021Updated 4 years ago
- Bro IDS programs collection.☆146Oct 16, 2019Updated 6 years ago
- Analysis scripts for the Bro Intrusion Detection System☆59Feb 26, 2014Updated 11 years ago
- Python script that gets IOC from MISP and converts it into BRO intel files.☆13Apr 17, 2016Updated 9 years ago
- Enables Zeek to communicate with Tenzir☆11Jul 20, 2023Updated 2 years ago
- A framework that correlates Bro events☆18Oct 25, 2013Updated 12 years ago
- module for osquery to load Bro logs into tables☆28Apr 28, 2015Updated 10 years ago
- Zeek support for Community ID flow hashing.☆37Jul 11, 2023Updated 2 years ago
- Remote Desktop Client Fingerprint script for Zeek. Based off of https://github.com/0x4D31/fatt☆40Jun 20, 2023Updated 2 years ago
- PacketSled's Bro AMQP Writer Plugin☆11Aug 5, 2016Updated 9 years ago
- Bro things..☆15Oct 23, 2015Updated 10 years ago
- A Zeek plugin to POST logs over HTTP.☆13Feb 10, 2020Updated 6 years ago
- ☆21Oct 16, 2021Updated 4 years ago
- Various Bro scripts☆37May 20, 2014Updated 11 years ago