Pinned Repositories
aaalm
Generate network maps from packet captures
barnyard2-extra
Barnyard2 with "Extra Data" support and other enhancements.
bro-json-to-tsv
(DEPRICATED) Bro JSON to TSV converter.
bzar
A set of Zeek scripts to detect ATT&CK techniques.
Cortex-IR-Incident-Fetcher
The program helps fetched incidents from Cortex XDR IR and index to ElasticSearch for report
Daemonlogger
The Official Github Repository of Daemonlogger
daemonloggerdaq
Daemonlogger modified to use DAQ, primarily for listening on multiple interfaces
ecs-mapping
Grab bag of resources for mapping data to the Elastic Common Schema (ECS)
ElastAlertGrouper
A feature extension to ease the automation of Threat Hunting with ElastAlert and the ELK Stack
email-parser
Trying to parse some SMTP with Python 2.x
CyberTaoFlow's Repositories
CyberTaoFlow/aaalm
Generate network maps from packet captures
CyberTaoFlow/barnyard2-extra
Barnyard2 with "Extra Data" support and other enhancements.
CyberTaoFlow/Cortex-IR-Incident-Fetcher
The program helps fetched incidents from Cortex XDR IR and index to ElasticSearch for report
CyberTaoFlow/Daemonlogger
The Official Github Repository of Daemonlogger
CyberTaoFlow/graphdatamap
Graph Data Map Project
CyberTaoFlow/gulp
Lossless Gigabit Remote Packet Capture With Linux
CyberTaoFlow/hosom_bro-file-extraction
Convenience wrapper for extracting files in bro
CyberTaoFlow/IBAN-Validator-with-regex
Iban Validation Program
CyberTaoFlow/meer
Meer (GPLv2) is a dedicated "spooler" for the Suricata & Sagan EVE output formats.
CyberTaoFlow/monopticon
Monitor ethernet traffic in real time with a 3D backend.
CyberTaoFlow/mt103
Parse MT103 messages from the Swift payments network
CyberTaoFlow/netbase
Netbase, short for Network Baseliner is a Zeek framework for making and recording quantitative observations about network device activity.
CyberTaoFlow/PacketSorter
TCP packet sorter
CyberTaoFlow/readonlyrest-docs
Official Documentation of ReadonlyREST Plugin
CyberTaoFlow/sagan-rules
Rule sets for Sagan
CyberTaoFlow/suricata-rules
Suricata IDS rules
CyberTaoFlow/zeek-httpattacks
This module detects HTTP requests that are non RFC compliant and used for smuggling
CyberTaoFlow/zeek-scripts
zeek-scripts
CyberTaoFlow/zeek_anomaly_detector
An anomaly detector for conn.log files in Zeek/Bro. Completely Automatic
CyberTaoFlow/bitscout
CyberTaoFlow/BusinessSpew
The BS Generator creates blocks of valid English language sentences comprised solely of jargon, slang and nonsense.
CyberTaoFlow/captop
Utility to measure the performance of pcap network interfaces.
CyberTaoFlow/Decept
Decept Network Protocol Proxy
CyberTaoFlow/eml_parser
python eml parser module
CyberTaoFlow/flow_labels
Provides a mechanism for loading knowledge about a monitored environment into Zeek.
CyberTaoFlow/generic-parser
A Single Library Parser to extract meta information,static analysis and detect macros within the files.
CyberTaoFlow/libflowbypass
Experimental XDP bypass stuff
CyberTaoFlow/port-mirror
A Windows port to the port-mirror utility
CyberTaoFlow/python-elk
This is a super-basic set of scripts to show "simple" ways to get data into or out of the Elastic stack using python.
CyberTaoFlow/rock-suricata
Repo for suricata signatures and signature deployment workflow.