All Projects → zeek-docs → Similar Projects or Alternatives

317 Open source projects that are alternatives of or similar to zeek-docs

Zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.
Stars: ✭ 4,180 (+10095.12%)
Mutual labels:  pcap, dfir, bro, network-monitoring, nsm, zeek
Zeek-Network-Security-Monitor
A Zeek Network Security Monitor tutorial that will cover the basics of creating a Zeek instance on your network in addition to all of the necessary hardware and setup and finally provide some examples of how you can use the power of Zeek to have absolute control over your network.
Stars: ✭ 38 (-7.32%)
Mutual labels:  pcap, bro, network-monitoring, zeek
Ivre
Network recon framework, published by @cea-sec & @ANSSI-FR. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, collect and analyse network intelligence from your sensors, and much more!
Stars: ✭ 2,331 (+5585.37%)
Mutual labels:  bro, network-monitoring, zeek
ivre
Network recon framework. Build your own, self-hosted and fully-controlled alternatives to Shodan / ZoomEye / Censys and GreyNoise, run your Passive DNS service, collect and analyse network intelligence from your sensors, and much more!
Stars: ✭ 2,712 (+6514.63%)
Mutual labels:  bro, network-monitoring, zeek
Arkime
Arkime (formerly Moloch) is an open source, large scale, full packet capturing, indexing, and database system.
Stars: ✭ 4,994 (+12080.49%)
Mutual labels:  pcap, network-monitoring, nsm
NetworkAlarm
A tool to monitor local network traffic for possible security vulnerabilities. Warns user against possible nmap scans, Nikto scans, credentials sent in-the-clear, and shellshock attacks. Currently supports live monitoring and network capture (pcap) scanning.
Stars: ✭ 17 (-58.54%)
Mutual labels:  pcap, network-monitoring
network-tools
Network Tools
Stars: ✭ 27 (-34.15%)
Mutual labels:  pcap, network-monitoring
flow-indexer
Flow-Indexer indexes flows found in chunked log files from bro,nfdump,syslog, or pcap files
Stars: ✭ 43 (+4.88%)
Mutual labels:  pcap, bro
awesome-bro
Useful resources for Zeek(https://zeek.org/) (Bro(http://bro.org/))
Stars: ✭ 31 (-24.39%)
Mutual labels:  bro, nsm
Suricata
Suricata git repository maintained by the OISF
Stars: ✭ 2,274 (+5446.34%)
Mutual labels:  network-monitoring, nsm
Passer
Passive service locator, a python sniffer that identifies servers, clients, names and much more
Stars: ✭ 144 (+251.22%)
Mutual labels:  pcap, network-monitoring
docker-zeek
Zeek IDS Dockerfile
Stars: ✭ 82 (+100%)
Mutual labels:  network-monitoring, zeek
Security Onion
Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
Stars: ✭ 2,956 (+7109.76%)
Mutual labels:  dfir, nsm
Nfstream
NFStream: a Flexible Network Data Analysis Framework.
Stars: ✭ 622 (+1417.07%)
Mutual labels:  pcap, network-monitoring
MegaDev
Bro IDS + ELK Stack to detect and block data exfiltration
Stars: ✭ 46 (+12.2%)
Mutual labels:  bro, zeek
Malcom
Malcom - Malware Communications Analyzer
Stars: ✭ 988 (+2309.76%)
Mutual labels:  pcap, dfir
brimcap
Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)
Stars: ✭ 22 (-46.34%)
Mutual labels:  pcap, zeek
graylog-zeek-content-pack
BRO/Zeek IDS content pack contains pipeline rules, a stream, a dashboard displaying interesting activity, and a syslog tcp input to capture and index BRO/Zeek logs coming from a remote sensor.
Stars: ✭ 18 (-56.1%)
Mutual labels:  bro, zeek
Poseidon
Poseidon is a python-based application that leverages software defined networks (SDN) to acquire and then feed network traffic to a number of machine learning techniques. The machine learning algorithms classify and predict the type of device.
Stars: ✭ 310 (+656.1%)
Mutual labels:  pcap, network-monitoring
Packages
The default package source of the Zeek Package Manager
Stars: ✭ 94 (+129.27%)
Mutual labels:  pcap, network-monitoring
Go Iex
A Go library for accessing the IEX Developer API.
Stars: ✭ 87 (+112.2%)
Mutual labels:  pcap
Genet
Graphical network analyzer powered by web technologies
Stars: ✭ 195 (+375.61%)
Mutual labels:  pcap
Netboot
Packages and utilities for network booting
Stars: ✭ 1,157 (+2721.95%)
Mutual labels:  pcap
Hcxtools
Portable (that doesn't include proprietary/commercial operating systems) solution for conversion of cap/pcap/pcapng (gz compressed) WiFi dump files to hashcat formats (recommended by hashcat) and to John the Ripper formats. hcx: h = hash, c = convert and calculate candidates, x = different hashtypes
Stars: ✭ 1,121 (+2634.15%)
Mutual labels:  pcap
Packrat
Live system forensic collector
Stars: ✭ 16 (-60.98%)
Mutual labels:  dfir
Quantuminsert
Quantum Insert
Stars: ✭ 186 (+353.66%)
Mutual labels:  pcap
Rtpdump
Extract audio file from RTP streams in pcap format
Stars: ✭ 54 (+31.71%)
Mutual labels:  pcap
Daggy
Daggy - Data Aggregation Utility. Open source, free, cross-platform, server-less, useful utility for remote or local data aggregation and streaming
Stars: ✭ 91 (+121.95%)
Mutual labels:  pcap
Cuishark
A protocol analyzer like a wireshark on CUI. cuishark is using libwireshark to analyze packets. https://cuishark.slankdev.net
Stars: ✭ 208 (+407.32%)
Mutual labels:  pcap
Networkml
Machine learning plugins for network traffic
Stars: ✭ 73 (+78.05%)
Mutual labels:  pcap
pyarascanner
A simple many-rules to many-files YARA scanner for incident response or malware zoos.
Stars: ✭ 23 (-43.9%)
Mutual labels:  dfir
Potiron
Potiron - Normalize, Index and Visualize Network Capture
Stars: ✭ 66 (+60.98%)
Mutual labels:  pcap
Winshark
A wireshark plugin to instrument ETW
Stars: ✭ 191 (+365.85%)
Mutual labels:  pcap
Pcapxray
❄️ PcapXray - A Network Forensics Tool - To visualize a Packet Capture offline as a Network Diagram including device identification, highlight important communication and file extraction
Stars: ✭ 1,096 (+2573.17%)
Mutual labels:  pcap
TheHiveHooks
This is a python tool aiming to make using TheHive webhooks easier.
Stars: ✭ 22 (-46.34%)
Mutual labels:  dfir
Skydive
An open source real-time network topology and protocols analyzer
Stars: ✭ 2,086 (+4987.8%)
Mutual labels:  pcap
Net2pcap
Net2PCAP is a simple network-to-pcap capture file for Linux. Its goal is to be as simple as possible to be used in hostile environments
Stars: ✭ 36 (-12.2%)
Mutual labels:  pcap
Hcxdumptool
Small tool to capture packets from wlan devices.
Stars: ✭ 945 (+2204.88%)
Mutual labels:  pcap
Joincap
Merge multiple pcap files together, gracefully.
Stars: ✭ 159 (+287.8%)
Mutual labels:  pcap
Crafter
🔬 An R package to work with PCAPs
Stars: ✭ 27 (-34.15%)
Mutual labels:  pcap
Pcapfs
A FUSE module to mount captured network data
Stars: ✭ 17 (-58.54%)
Mutual labels:  pcap
Homer
HOMER - 100% Open-Source SIP / VoIP Packet Capture & Monitoring
Stars: ✭ 855 (+1985.37%)
Mutual labels:  pcap
Node pcap
libpcap bindings for node
Stars: ✭ 849 (+1970.73%)
Mutual labels:  pcap
NetTool
macOS 状态栏小工具实时显示网速. macOS menubar tool to monitor network speed.
Stars: ✭ 74 (+80.49%)
Mutual labels:  network-monitoring
d4-core
D4 core software (server and sample sensor client)
Stars: ✭ 40 (-2.44%)
Mutual labels:  network-monitoring
EventTranscript.db-Research
A repo for centralizing ongoing research on the new Windows 10/11 DFIR artifact, EventTranscript.db.
Stars: ✭ 33 (-19.51%)
Mutual labels:  dfir
Udpreplay
Replay UDP packets from a pcap file
Stars: ✭ 135 (+229.27%)
Mutual labels:  pcap
Tapirx
Free and open-source medical device discovery and identification
Stars: ✭ 19 (-53.66%)
Mutual labels:  pcap
Kamene
Network packet and pcap file crafting/sniffing/manipulation/visualization security tool. Originally forked from scapy in 2015 and providing python3 compatibility since then.
Stars: ✭ 827 (+1917.07%)
Mutual labels:  pcap
Libpcap
the LIBpcap interface to various kernel packet capture mechanism
Stars: ✭ 1,785 (+4253.66%)
Mutual labels:  pcap
Scapy
Scapy: the Python-based interactive packet manipulation program & library. Supports Python 2 & Python 3.
Stars: ✭ 6,932 (+16807.32%)
Mutual labels:  pcap
Tcpreplay
Pcap editing and replay tools for *NIX and Windows - Users please download source from
Stars: ✭ 745 (+1717.07%)
Mutual labels:  pcap
CCXDigger
The CyberCX Digger project is designed to help Australian organisations determine if they have been impacted by certain high profile cyber security incidents. Digger provides threat hunting functionality packaged in a simple-to-use tool, allowing users to detect certain attacker activities; all for free.
Stars: ✭ 45 (+9.76%)
Mutual labels:  dfir
Tcpdump
the TCPdump network dissector
Stars: ✭ 1,731 (+4121.95%)
Mutual labels:  pcap
Pcap Analyzer
Python编写的可视化的离线数据包分析器
Stars: ✭ 694 (+1592.68%)
Mutual labels:  pcap
Libtins
High-level, multiplatform C++ network packet sniffing and crafting library.
Stars: ✭ 1,609 (+3824.39%)
Mutual labels:  pcap
Sniffglue
Secure multithreaded packet sniffer
Stars: ✭ 651 (+1487.8%)
Mutual labels:  pcap
ipdecap
Decapsulate traffic encapsulated within GRE, IPIP, 6in4, ESP (ipsec) protocols, can also remove IEEE 802.1Q (virtual lan) header. Works with pcap files.
Stars: ✭ 32 (-21.95%)
Mutual labels:  pcap
Pcapviz
Visualize network topologies and collect graph statistics based on pcap files
Stars: ✭ 247 (+502.44%)
Mutual labels:  pcap
Captagent
100% Open-Source Packet Capture Agent for HEP
Stars: ✭ 116 (+182.93%)
Mutual labels:  pcap
1-60 of 317 similar projects