Repository navigation

#

zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

C++
7166
1 天前

Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, build your taylor-made EASM tool, collect and analyse network intelligence from your sensors, and much more! Uses Nmap, Masscan, Zeek, p0f, ProjectDiscovery tools, etc.

Python
3816
4 天前

Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

Python
2236
10 天前

Logging Made Easy (LME) is a no cost, open source platform that centralizes log collection, enhances threat detection, and enables real-time alerting, helping small to medium-sized organizations secure their infrastructure. LME Docs can be found at https://cisagov.github.io/lme-docs/docs/

Python
1117
1 天前

Slips, a free software behavioral Python intrusion prevention system (IDS/IPS) that uses machine learning to detect malicious behaviors in the network traffic. Stratosphere Laboratory, AIC, FEL, CVUT in Prague.

Python
829
2 天前

This project is a SIEM with SIRP and Threat Intel, all in one.

Shell
462
10 个月前

Zeek Analysis Tools (ZAT): Processing and analysis of Zeek network data with Pandas, scikit-learn, Kafka and Spark

Jupyter Notebook
446
2 年前

Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.

Go
390
8 天前

C++ parser generator for dissecting protocols & files.

C++
282
3 天前

🚌 Threat Bus – A threat intelligence dissemination layer for open-source security tools.

Python
264
3 年前

DynamiteNSM is a free Network Security Monitor developed by Dynamite Analytics to enable network visibility and advanced cyber threat detection

Python
171
2 年前

Threat Hunting Toolkit is a Swiss Army knife for threat hunting, log processing, and security-focused data science

Shell
144
4 天前

Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings

Zeek
122
4 年前

Extract files from network traffic with Zeek.

Zeek
102
6 年前

Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)

Go
88
5 个月前

Open source endpoint agent providing host information to Zeek. [v2]

C++
86
1 个月前