neslog's repositories

3aj-lib

Proof of concept communications from C# via a web browser process

Language:C#License:MITStargazers:0Issues:2Issues:0

atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.

Language:PowerShellLicense:MITStargazers:0Issues:2Issues:0

AWS_zeek

Deploy zeek with a mirror

License:Apache-2.0Stargazers:0Issues:1Issues:0

bro-osquery

Bro integration with osquery

Language:BroStargazers:0Issues:2Issues:0

bro-packages

LIsting of Bro Packages

Stargazers:0Issues:2Issues:0

bro-sysmon

How to Zeek Sysmon Logs!

Language:BroLicense:BSD-3-ClauseStargazers:0Issues:1Issues:0

bro_scripts

Various Bro scripts

Language:BroStargazers:0Issues:2Issues:0

BroSysmon-Vagrant

Vagrant file to create Win32 VM for Bro-Sysmon Environment.

Language:RubyStargazers:0Issues:2Issues:0

DET

(extensible) Data Exfiltration Toolkit (DET)

Language:PythonLicense:MITStargazers:0Issues:2Issues:0

intel_feeds

Gathering list of intel feeds to use

Stargazers:0Issues:2Issues:0

ja3

JA3 is a standard for creating SSL client fingerprints in an easy to produce and shareable way.

Language:PythonLicense:BSD-3-ClauseStargazers:0Issues:2Issues:0
Language:BroStargazers:0Issues:2Issues:0

ja3_ua

JA3 mapping to HTTP UserAgent

Language:BroStargazers:0Issues:2Issues:0

malwoverview

Malwoverview.py is a first response tool to perform an initial and quick triage on either a directory containing malware samples or a specific malware sample.

Language:PythonLicense:GPL-3.0Stargazers:0Issues:2Issues:0

misc-Hyara

Yara rule making tool (IDA Plugin)

Language:PythonStargazers:0Issues:2Issues:0

packages

The default package source of the Zeek Package Manager

Stargazers:0Issues:1Issues:0

puppet_bro

Puppet module for installing bro.

Language:PuppetStargazers:0Issues:2Issues:0

puppet_examples

Samples of Puppet manifests

Language:PuppetStargazers:0Issues:2Issues:0

RATs

Collection of Remote Administration Tool samples

Stargazers:0Issues:2Issues:0

raw

The missing link between spreadsheets and data visualization

Language:JavaScriptLicense:Apache-2.0Stargazers:0Issues:1Issues:0

sigma

Generic Signature Format for SIEM Systems

Language:PythonStargazers:0Issues:2Issues:0

spicy-noise

A Spicy protocol analyzer for WireGuard

Language:ZeekLicense:Apache-2.0Stargazers:0Issues:1Issues:0

suricata

Mirror of the official OISF Suricata git repository

Language:CLicense:GPL-2.0Stargazers:0Issues:2Issues:0

suricata-rpms

Suricata RPMs for CentOS/EL

Language:MakefileStargazers:0Issues:2Issues:0

tcpflow

TCP/IP packet demultiplexer

Language:C++License:GPL-3.0Stargazers:0Issues:2Issues:0

testssl

.exe which makes a few simple SSL calls

Language:C#Stargazers:0Issues:2Issues:0

the-endorser

An OSINT tool that allows you to draw out relationships between people on LinkedIn via endorsements/skills.

Language:PythonLicense:MITStargazers:0Issues:2Issues:0

vaw_decode

vawtrak traffic decoder

Language:PythonStargazers:0Issues:2Issues:0

zeek

Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.

License:NOASSERTIONStargazers:0Issues:0Issues:0

zeek-plugin-noise

Spicy-Noise implementation in Binpac.

Language:JavaScriptLicense:Apache-2.0Stargazers:0Issues:5Issues:0