Owner
corelight
36 indexierte Repositories · Auf GitHub ansehen
-
community-id-spec
An open standard for hashing network flows into identifiers, a.k.a "Community IDs".
Python · 197 Sterne
-
raspi-corelight
Corelight@Home script
Shell · 46 Sterne
-
zeek-community-id
Zeek support for Community ID flow hashing.
Zeek · 37 Sterne
-
cwrap
Auto wrap C and C++ functions with instrumentation
Perl · 34 Sterne
-
ecs-mapping
Mapping Corelight or Zeek data to Elastic Common Schema fields
33 Sterne
-
ripple20
A Zeek package for the passive detection of "Ripple20" vulnerabilities in the Treck TCP/IP stack.
Zeek · 32 Sterne
-
zeek-long-connections
Zeek package for tracking long connections to report them before they have completed.
Zeek · 31 Sterne
-
json-streaming-logs
Zeek package to create JSON formatted logs to stream into data analysis systems.
Zeek · 31 Sterne
-
suricata_exporter
A Prometheus Exporter for Suricata
Go · 27 Sterne
-
cve-2021-44228
Log4j Exploit Detection Logic for Zeek
Zeek · 19 Sterne
-
corelight-client
Corelight Sensor API command-line client
Python · 17 Sterne
-
json-tcp-lb
line based tcp load balancing proxy.
Go · 14 Sterne
-
zeek-quic
Bro analyzer that detects Google's QUIC protocol
JavaScript · 11 Sterne
-
ecs-logstash-mappings
Mapping Corelight or Zeek data to Elastic Common Schema logs
11 Sterne
-
top-dns
Top DNS Measurement for Bro
Zeek · 10 Sterne
-
zeek-spicy-openvpn
A Zeek OpenVPN protocol analyzer, based on Spicy.
Zeek · 9 Sterne
-
ecs-templates
Corelight or Zeek Elastic Common Schema Templates
Python · 9 Sterne
-
9 Sterne
-
zeekjs
ZeekJS - Experimental JavaScript support for Zeek.
C++ · 8 Sterne
-
zeek-openvpn
A Zeek OpenVPN protocol analyzer plugin.
JavaScript · 7 Sterne
- 16 weitere Repositories liegen auf Auf GitHub ansehen
-
Zeekified Offen
corelight/bro-protosigs#1 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/bro-hardware#1 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/top-dns#2 · 1 Kommentar · 1 Reaktion · 0 zugewiesene Personen ·
-
corelight/zeek-quic#3 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/zeek-globload#1 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/ztest#1 · 1 Kommentar · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/ztest#2 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/CVE-2021-38647#4 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/CVE-2022-23270-PPTP#1 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/ripple20#1 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/CVE-2022-24497#2 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/CVE-2022-3602#1 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/CVE-2022-24491#2 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/CVE-2022-24491#3 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
Update to Zeek v4.1 Offenenhancement
corelight/zeek-openvpn#4 · 0 Kommentare · 0 Reaktionen · 1 zugewiesene Person ·
-
enhancement zeek-tweak
corelight/zeek-community-id#3 · 19 Kommentare · 2 Reaktionen · 0 zugewiesene Personen ·
-
enhancement good first issue
corelight/zeek-community-id#19 · 1 Kommentar · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/plotcap#4 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
ipv6 support Offen
corelight/raspi-corelight#1 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/raspi-corelight#7 · 9 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/zeek-xor-exe-plugin#1 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/json-tcp-lb#7 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
bug question spec-ambiguity
corelight/community-id-spec#3 · 3 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
enhancement
corelight/community-id-spec#4 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
question
corelight/community-id-spec#9 · 2 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
Use case: anonymity Offenusecase
corelight/community-id-spec#10 · 1 Kommentar · 1 Reaktion · 0 zugewiesene Personen ·
-
enhancement
corelight/community-id-spec#11 · 1 Kommentar · 0 Reaktionen · 0 zugewiesene Personen ·
-
usecase
corelight/community-id-spec#13 · 0 Kommentare · 1 Reaktion · 0 zugewiesene Personen ·
-
Sharefulness - 4 tuple Offenenhancement
corelight/community-id-spec#21 · 3 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/community-id-spec#22 · 0 Kommentare · 4 Reaktionen · 0 zugewiesene Personen ·
-
enhancement
corelight/community-id-spec#23 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
bug
corelight/community-id-spec#32 · 1 Kommentar · 0 Reaktionen · 1 zugewiesene Person ·
-
enhancement spec-ambiguity
corelight/community-id-spec#33 · 3 Kommentare · 0 Reaktionen · 1 zugewiesene Person ·
-
corelight/community-id-spec#34 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
community ID decode Offen
corelight/community-id-spec#36 · 1 Kommentar · 0 Reaktionen · 0 zugewiesene Personen ·
-
good first issue
corelight/go-zeek-broker-ws#2 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/go-zeek-broker-ws#3 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
missing some rfc's OffenNeed PCAPs
corelight/zeek-spicy-stun#3 · 7 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
enhancement
corelight/zeek-spicy-stun#6 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/zeek-asyncrat-detector#4 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/zeek-long-connections#14 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/zeek-long-connections#15 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/zeek-long-connections#16 · 0 Kommentare · 1 Reaktion · 0 zugewiesene Personen ·
-
enhancement
corelight/cve-2021-44228#7 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
enhancement
corelight/cve-2021-44228#8 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/cve-2021-44228#23 · 1 Kommentar · 0 Reaktionen · 0 zugewiesene Personen ·
-
DNS exfil regexes Offenenhancement
corelight/cve-2021-44228#27 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
LDAPS fingerprinting Offenenhancement
corelight/cve-2021-44228#28 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
Parses wrong payload IP Offen
corelight/cve-2021-44228#30 · 2 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·
-
corelight/cve-2021-44228#32 · 0 Kommentare · 0 Reaktionen · 0 zugewiesene Personen ·