Pinned repositories
Repositories
-
espy
Endpoint detection for remote hosts for consumption by RITA and Elasticsearch
-
BeaKer
Beacon Kibana Executable Report. Aggregates Sysmon Network Events With Elasticsearch and Kibana
-
shell-lib
Shell Scripts Used Across ActiveCM Projects
-
rita
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
-
passer
Passive service locator, a python sniffer that identifies servers, clients, names and much more
-
-
zeek-log-transport
This script ships logs from Zeek to AI-Hunter
-
rita-bl
Real Intelligence Threat Analytics -- Blacklist Database
-
threat-hunting-labs
Collection of walkthroughs on various threat hunting techniques
-
zeekcfg
A node.cfg generator for zeekctl
-
bro-install Archived
An Installation Script for Bro IDS on Debian Based Systems
-
pi_project_installer
A support library and set of scripts to simplify installing software on the Raspberry Pi/Raspbian
-
mongo-diff
A Python script for diff'ing mongo databases
-
devprof
Device profile: Define acceptable amounts of traffic for your devices and see a report of outliers.
-
pi_show
Python script/library for displaying text and graphics on Raspberry Pi PiOled Hat
-
mgosec
A Small Helper Library For Securing MongoDB Connections with Golang
-
ipfix-rita Archived
Collect IPFIX / Netflow v9 Records and Ship them to RITA for Analysis
-
DBTest
Managed Integration Testing Dependencies via Docker for Go
-
-
bro-rita
A bro plugin for writing log data to MongoDB for use with RITA
-
bro-rita-test
Compares bro-rita against rita's built in parsing
-
docker-ca
A Docker Image For OpenSSL Certificate Authorities (For Testing)
-
rita-blacklist Archived
Real Intelligence Threat Analytics -- Blacklist Database