Corelight, Inc. (corelight)

Corelight, Inc.

corelight

Geek Repo

Corelight is the most powerful network visibility solution for information security professionals, founded by the creators of open-source Zeek.

Location:San Francisco, CA

Home Page:http://www.corelight.com

Github PK Tool:Github PK Tool

Corelight, Inc.'s repositories

ecs-mapping

Mapping Corelight or Zeek data to Elastic Common Schema fields

cve-2021-44228

Log4j Exploit Detection Logic for Zeek

Language:ZeekLicense:BSD-3-ClauseStargazers:18Issues:9Issues:21

log-add-http-post-bodies

Add POST body excerpt to Bro's HTTP log

Language:ZeekLicense:BSD-3-ClauseStargazers:14Issues:7Issues:0

json-tcp-lb

line based tcp load balancing proxy.

Language:GoLicense:BSD-3-ClauseStargazers:13Issues:7Issues:2

ecs-logstash-mappings

Mapping Corelight or Zeek data to Elastic Common Schema logs

License:BSD-3-ClauseStargazers:11Issues:8Issues:11

suricata_exporter

A Prometheus Exporter for Suricata

Language:GoLicense:BSD-3-ClauseStargazers:11Issues:4Issues:6

zeekjs

ZeekJS - Experimental JavaScript support for Zeek.

Language:C++License:BSD-3-ClauseStargazers:8Issues:6Issues:12

ecs-templates

Corelight or Zeek Elastic Common Schema Templates

Language:PythonLicense:BSD-3-ClauseStargazers:7Issues:7Issues:10

icannTLD

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and mark whether it's trusted or not. The source of the ICANN TLD's can be found here: https://publicsuffix.org/list/effective_tld_names.dat. The Trusted Domains list is a custom list, created by the user, to filter domains during searches.

Language:ZeekLicense:NOASSERTIONStargazers:4Issues:8Issues:0

http-more-files-names

Add more filenames to files.log from HTTP requests

Language:ZeekLicense:BSD-3-ClauseStargazers:2Issues:4Issues:0

hassh

Fingerprint SSH clients and servers.

Language:ZeekLicense:NOASSERTIONStargazers:1Issues:5Issues:1

zeek-asyncrat-detector

A Zeek based AsyncRAT malware detector.

Language:ShellLicense:BSD-3-ClauseStargazers:1Issues:9Issues:0

zeek-notice-telegram

Send Notices as messages over Telegram

Language:ZeekLicense:BSD-3-ClauseStargazers:1Issues:5Issues:1
License:MITStargazers:0Issues:4Issues:0
Language:ZeekLicense:BSD-3-ClauseStargazers:0Issues:3Issues:0

ExtendIntel

This package extends the Intel package to log more fields

Language:ZeekLicense:NOASSERTIONStargazers:0Issues:0Issues:0
Language:ZeekLicense:BSD-3-ClauseStargazers:0Issues:0Issues:0

terraform-aws-enrichment

Terraform for Corelight's AWS Cloud Enrichment.

Language:HCLLicense:MITStargazers:0Issues:0Issues:0

terraform-aws-sensor

Terraform for Corelight's AWS Cloud Sensor Deployment.

Stargazers:0Issues:0Issues:0

terraform-azure-enrichment

Terraform for Corelight's Azure Cloud Enrichment.

Language:HCLLicense:MITStargazers:0Issues:0Issues:0

terraform-azure-sensor

Terraform for Corelight's Azure Cloud Sensor Deployment.

Stargazers:0Issues:0Issues:0

terraform-gcp-enrichment

Terraform for Corelight's GCP Cloud Enrichment.

Language:HCLLicense:MITStargazers:0Issues:0Issues:0

terraform-gcp-sensor

Terraform for Corelight's GCP Cloud Sensor Deployment.

Language:HCLLicense:MITStargazers:0Issues:0Issues:0
Language:ZeekLicense:NOASSERTIONStargazers:0Issues:5Issues:0
Language:ZeekLicense:NOASSERTIONStargazers:0Issues:5Issues:0
Language:ZeekLicense:NOASSERTIONStargazers:0Issues:5Issues:0

Zeek-Endpoint-Enrichment-conn

Enrich the conn.log with EDR data

Language:ZeekLicense:NOASSERTIONStargazers:0Issues:5Issues:0
Language:C++License:BSD-3-ClauseStargazers:0Issues:2Issues:0

zeek-strrat-detector

A Zeek based STRRAT malware detector.

Language:CMakeLicense:BSD-3-ClauseStargazers:0Issues:0Issues:0