Here are
50 public repositories
matching this topic...
Arkime (formerly Moloch) is an open source, large scale, full packet capturing, indexing, and database system.
Updated
Jun 3, 2022
JavaScript
Security Onion 16.04 - Linux distro for threat hunting, enterprise security monitoring, and log management
Suricata git repository maintained by the OISF
The Hybrid/Multi-cloud IP Service Mesh
Web Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search
Updated
May 21, 2022
Rust
The tool for updating your Suricata rules.
Updated
May 31, 2022
Python
Updated
May 30, 2022
Shell
The default package source of the Zeek Package Manager
Suricata rules for network anomaly detection
Cyber Defence Monitoring Course Suite :: Suricata, Moloch and others
Updated
Jun 1, 2022
Jupyter Notebook
Assists music production by grouping standalone programs into sessions. Community version of "Non Session Manager".
Threat Hunting with ELK Workshop (InfoSecWorld 2017)
Updated
Oct 31, 2017
PowerShell
Mapping NSM rules to MITRE ATT&CK
A package manager for Zeek
Updated
Jun 3, 2022
Python
Updated
May 15, 2020
Zeek
Application and service identification rules for Suricata
Updated
Jan 17, 2018
Python
A Docker container for Moloch based on ubuntu
Updated
Jan 24, 2022
Shell
McAfee SIEM API Python wrapper
Updated
Aug 10, 2021
Python
Network Service Mesh examples repo
Updated
Oct 28, 2021
Makefile
Materials for the BSides NoVA/Charleston 2018 Bro Workshop
Updated
Oct 22, 2021
Dockerfile
Monitors Bro NSM logs and sends them to Elasticsearch
Updated
Sep 3, 2017
Python
Suricata rule and intel index
A curated list of FOSS software appliances for building a SOC
Collect and parse Bro logs with Logstash+Filebeat
Detect weird services on a network.
A saltstack formula to install BRO network security monitor on RHEL or Debian based systems
Updated
Aug 18, 2019
SaltStack
Improve this page
Add a description, image, and links to the
nsm
topic page so that developers can more easily learn about it.
Curate this topic
Add this topic to your repo
To associate your repository with the
nsm
topic, visit your repo's landing page and select "manage topics."
Learn more
You can’t perform that action at this time.
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.
We currently have coverage for raw packets, pop3, and dns (in a fashion). It would be good to expand our coverage to other major protocols. I'm currently thinking at least the following:
On top of that, we should take a look at the coverage statistics we're getting from oss-fuzz and determine where the ga