A lightweight tool to score network traffic and flag anomalies
-
Updated
Aug 7, 2024 - Go
A lightweight tool to score network traffic and flag anomalies
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
Utility for parsing Bro log files into CSV or JSON format
Dovehawk is a Zeek module that automatically imports MISP indicators and reports Sightings
Simple logfile parser for Bro IDS
Look for un-sinkholed C&C IPs in your Bro logs (from Bambanek Consulting C&C master list)
brostash: Linux distribution based on Debian and focusing on network security events collection
Bro IDS Dockerfile
Patches for cross-compiling Bro IDS with Buildroot.
🐦 A fluentd config for zeek
Brostash Logstash pipeline
An Ubuntu 16.04 build containing Suricata, PulledPork, Bro, and Splunk
Add a description, image, and links to the bro-ids topic page so that developers can more easily learn about it.
To associate your repository with the bro-ids topic, visit your repo's landing page and select "manage topics."