All Projects → Operation Wocao → Similar Projects or Alternatives

124 Open source projects that are alternatives of or similar to Operation Wocao

S1EM
This project is a SIEM with SIRP and Threat Intel, all in one.
Stars: ✭ 270 (+831.03%)
Mutual labels:  suricata, yara
Hamburglar
Hamburglar -- collect useful information from urls, directories, and files
Stars: ✭ 321 (+1006.9%)
Mutual labels:  yara
YaraSyntax
YARA package for Sublime Text
Stars: ✭ 15 (-48.28%)
Mutual labels:  yara
python-icap-yara
An ICAP Server with yara scanner for URL and content.
Stars: ✭ 50 (+72.41%)
Mutual labels:  yara
nsm-attack
Mapping NSM rules to MITRE ATT&CK
Stars: ✭ 53 (+82.76%)
Mutual labels:  suricata
Stoq
An open source framework for enterprise level automated analysis.
Stars: ✭ 352 (+1113.79%)
Mutual labels:  yara
brimcap
Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)
Stars: ✭ 22 (-24.14%)
Mutual labels:  suricata
Multiscanner
Modular file scanning/analysis framework
Stars: ✭ 494 (+1603.45%)
Mutual labels:  yara
Freki
🐺 Malware analysis platform
Stars: ✭ 285 (+882.76%)
Mutual labels:  yara
Hyara
Yara rule making tool (IDA Pro & Binary Ninja & Cutter Plugin)
Stars: ✭ 142 (+389.66%)
Mutual labels:  yara
PhishingKit-Yara-Search
Yara scan Phishing Kit's Zip archive(s)
Stars: ✭ 24 (-17.24%)
Mutual labels:  yara
MeltingPot
A tool to cluster similar executables (PEs, DEXs, and etc), extract common signature, and generate Yara patterns for malware detection.
Stars: ✭ 23 (-20.69%)
Mutual labels:  yara
Strelka
Real-time, container-based file scanning at enterprise scale
Stars: ✭ 387 (+1234.48%)
Mutual labels:  yara
docker-suricata
A Suricata Docker image.
Stars: ✭ 120 (+313.79%)
Mutual labels:  suricata
Die Engine
DIE engine
Stars: ✭ 648 (+2134.48%)
Mutual labels:  yara
yaramanager
Simple yara rule manager
Stars: ✭ 60 (+106.9%)
Mutual labels:  yara
Qnsm
QNSM is network security monitoring framework based on DPDK.
Stars: ✭ 334 (+1051.72%)
Mutual labels:  suricata
factual-rules-generator
Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.
Stars: ✭ 62 (+113.79%)
Mutual labels:  yara
Ghidra scripts
Scripts for the Ghidra software reverse engineering suite.
Stars: ✭ 732 (+2424.14%)
Mutual labels:  yara
altprobe
collector for XDR and security posture service
Stars: ✭ 62 (+113.79%)
Mutual labels:  suricata
Evebox
Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search
Stars: ✭ 286 (+886.21%)
Mutual labels:  suricata
TheBriarPatch
An extremely crude, lightweight Web Frontend for Suricata/Bro to be used with BriarIDS
Stars: ✭ 21 (-27.59%)
Mutual labels:  suricata
Peframe
PEframe is a open source tool to perform static analysis on Portable Executable malware and malicious MS Office documents.
Stars: ✭ 472 (+1527.59%)
Mutual labels:  yara
Mquery
YARA malware query accelerator (web frontend)
Stars: ✭ 264 (+810.34%)
Mutual labels:  yara
YaraSharp
C# wrapper around the Yara pattern matching library
Stars: ✭ 29 (+0%)
Mutual labels:  yara
detection
Detection in the form of Yara, Snort and ClamAV signatures.
Stars: ✭ 70 (+141.38%)
Mutual labels:  yara
yarasploit
YaraSploit is a collection of Yara rules generated from Metasploit framework shellcodes.
Stars: ✭ 31 (+6.9%)
Mutual labels:  yara
Suricata Rules
Suricata IDS rules 用来检测红队渗透/恶意行为等,支持检测CobaltStrike/MSF/Empire/DNS隧道/Weevely/菜刀/冰蝎/挖矿/反弹shell/ICMP隧道等
Stars: ✭ 397 (+1268.97%)
Mutual labels:  suricata
yara-rules
Yara rules written by me, for free use.
Stars: ✭ 13 (-55.17%)
Mutual labels:  yara
Mitigating Web Shells
Guidance for mitigation web shells. #nsacyber
Stars: ✭ 698 (+2306.9%)
Mutual labels:  yara
static file analysis
Analysis of file (doc, pdf, exe, ...) in deep (emmbedded file(s)) with clamscan and yara rules
Stars: ✭ 34 (+17.24%)
Mutual labels:  yara
Yara Python
The Python interface for YARA
Stars: ✭ 368 (+1168.97%)
Mutual labels:  yara
gonids
gonids is a library to parse IDS rules, with a focus primarily on Suricata rule compatibility. There is a discussion forum available that you can join on Google Groups: https://groups.google.com/forum/#!topic/gonids/
Stars: ✭ 140 (+382.76%)
Mutual labels:  suricata
Yargen
yarGen is a generator for YARA rules
Stars: ✭ 795 (+2641.38%)
Mutual labels:  yara
apooxml
Generate YARA rules for OOXML documents.
Stars: ✭ 34 (+17.24%)
Mutual labels:  yara
Pulledpork
Pulled Pork for Snort and Suricata rule management (from Google code)
Stars: ✭ 339 (+1068.97%)
Mutual labels:  suricata
ThreatKB
Knowledge base workflow management for YARA rules and C2 artifacts (IP, DNS, SSL) (ALPHA STATE AT THE MOMENT)
Stars: ✭ 68 (+134.48%)
Mutual labels:  yara
Sunburst countermeasures
Stars: ✭ 519 (+1689.66%)
Mutual labels:  yara
PhishingKit-Yara-Rules
Repository of Yara rules dedicated to Phishing Kits Zip files
Stars: ✭ 71 (+144.83%)
Mutual labels:  yara
Icewater
16,432 Free Yara rules created by
Stars: ✭ 324 (+1017.24%)
Mutual labels:  yara
vagrant-ids
An Ubuntu 16.04 build containing Suricata, PulledPork, Bro, and Splunk
Stars: ✭ 21 (-27.59%)
Mutual labels:  suricata
Didierstevenssuite
Please no pull requests for this repository. Thanks!
Stars: ✭ 856 (+2851.72%)
Mutual labels:  yara
Funnel
Funnel is a lightweight yara-based feed scraper
Stars: ✭ 38 (+31.03%)
Mutual labels:  yara
Python Iocextract
Defanged Indicator of Compromise (IOC) Extractor.
Stars: ✭ 300 (+934.48%)
Mutual labels:  yara
yara-rust
Rust bindings for VirusTotal/Yara
Stars: ✭ 35 (+20.69%)
Mutual labels:  yara
Yara
The pattern matching swiss knife
Stars: ✭ 5,209 (+17862.07%)
Mutual labels:  yara
swisscheese
Exploits for YARA 3.7.1 & 3.8.1
Stars: ✭ 26 (-10.34%)
Mutual labels:  yara
Yara Rules
Repository of YARA rules made by McAfee ATR Team
Stars: ✭ 283 (+875.86%)
Mutual labels:  yara
rdppot
RDP honeypot
Stars: ✭ 55 (+89.66%)
Mutual labels:  suricata
Selks
A Suricata based IDS/IPS distro
Stars: ✭ 707 (+2337.93%)
Mutual labels:  suricata
yara-validator
Validates yara rules and tries to repair the broken ones.
Stars: ✭ 37 (+27.59%)
Mutual labels:  yara
Reversinglabs Yara Rules
ReversingLabs YARA Rules
Stars: ✭ 280 (+865.52%)
Mutual labels:  yara
S2AN
S2AN - Mapper of Sigma/Suricata Rules/Signatures ➡️ MITRE ATT&CK Navigator
Stars: ✭ 70 (+141.38%)
Mutual labels:  suricata
Threatingestor
Extract and aggregate threat intelligence.
Stars: ✭ 439 (+1413.79%)
Mutual labels:  yara
mole
Yara powered NIDS with high speed packet capture powered by PF_RING
Stars: ✭ 51 (+75.86%)
Mutual labels:  yara
Yobi
Yara Based Detection Engine for web browsers
Stars: ✭ 39 (+34.48%)
Mutual labels:  yara
Iocs
IoC's, PCRE's, YARA's etc
Stars: ✭ 15 (-48.28%)
Mutual labels:  yara
Holmes Totem
Investigation Planner for fast running analysis with predictable execution time. For example, static analysis.
Stars: ✭ 25 (-13.79%)
Mutual labels:  yara
Manalyze
A static analyzer for PE executables.
Stars: ✭ 701 (+2317.24%)
Mutual labels:  yara
Scirius
Scirius is a web application for Suricata ruleset management.
Stars: ✭ 435 (+1400%)
Mutual labels:  suricata
1-60 of 124 similar projects