Repository navigation

#

zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

C++
7076
6 小时前

Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.

Python
3791
1 个月前

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

Python
2196
12 天前

Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations secure their infrastructure. LME Docs can be found at https://cisagov.github.io/lme-docs/docs/

Python
1097
11 小时前

Slips, a free software behavioral Python intrusion prevention system (IDS/IPS) that uses machine learning to detect malicious behaviors in the network traffic. Stratosphere Laboratory, AIC, FEL, CVUT in Prague.

Python
824
5 小时前

This project is a SIEM with SIRP and Threat Intel, all in one.

Shell
460
9 个月前

Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark

Jupyter Notebook
441
2 年前

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Go
354
1 天前

C++ parser generator for dissecting protocols & files.

C++
276
9 小时前

🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.

Python
263
2 年前

DynamiteNSM is a free Network Security Monitor developed by Dynamite Analytics to enable network visibility and advanced cyber threat detection

Python
171
2 年前

Threat Hunting Toolkit is a Swiss Army knife for threat hunting, log processing, and security-focused data science

Shell
144
7 天前

Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings

Zeek
121
4 年前

Extract files from network traffic with Zeek.

Zeek
101
5 年前

Open source endpoint agent providing host information to Zeek. [v2]

C++
85
2 天前

Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)

Go
85
4 个月前