Pinned Repositories
bro-auth
Authentication framework for Bro IDS.
bro-napatech
Napatech packet source plugin for Bro
bro-otx
Integrate Zeek with Alienvault OTX
bro-phishing
Detect Phishing with Bro IDS
bro-scripts
Bro stuff.
file-extraction
Extract files from network traffic with Zeek.
honeycred
Utility to inject honey tokens into lsass.
odd-services
Detect weird services on a network.
PunkSpiderSearch
Python Script that allows you to search PunkSpider in bulk requests and then output to a csv file or stdout.
svalinn
Windows Password Filter
hosom's Repositories
hosom/file-extraction
Extract files from network traffic with Zeek.
hosom/bro-otx
Integrate Zeek with Alienvault OTX
hosom/bro-ja3
ja3 ssl fingerprinting for bro
hosom/bro-oui
Add an OUI lookup to Bro IDS.
hosom/dummy-connections
Create connection records without having real connections.
hosom/log-filters
Common log filters for Zeek IDS
hosom/opencanary
Modular and decentralised honeypot
hosom/bro-cron
Schedule shell commands with Bro.
hosom/bro-environment
Learn and document your environment with Bro IDS.
hosom/bro-packages
Bro packages. Possibly unstable. I release here before anywhere else.
hosom/broctl
Tool for managing Bro deployments.
hosom/brointelutils
Utilities for Bro Intel Sources
hosom/broker
Bro's Messaging Library
hosom/cbapi-python
Carbon Black API - Python language bindings
hosom/docker-bro
Bro IDS Dockerfile
hosom/heimdall
very simple blocklist daemon
hosom/known-dhcp-nets
Log DHCP networks seen assigned by DHCP servers
hosom/nrol-39-logo
A vector PDF of the official mission logo of NROL-39
hosom/ntdedupe
napatech based packet deduplication tool
hosom/octokit.rb
Ruby toolkit for the GitHub API
hosom/packages
The default package source of the Zeek Package Manager
hosom/recently-compiled-pes
Detect PE files with a recent compile time.
hosom/stenographer
Stenographer is a packet capture solution which aims to quickly spool all packets to disk, then provide simple, fast access to subsets of those packets. Discussion/announcements at stenographer@googlegroups.com
hosom/tailscale-client-go
A client implementation for the Tailscale HTTP API
hosom/ufbuilder
Shell utilities to generate self extracting installers for the Splunk Universal Forwarder.
hosom/vault-ruby
The official Ruby client for HashiCorp's Vault
hosom/vscode_notes_template
Template repository for building notebooks in vscode
hosom/windows-event-forwarding
A repository for using windows event forwarding for incident detection and response
hosom/WindowsEventForwarding
Documentation and files for Windows Event Forwarding
hosom/zeek
Zeek is a powerful network analysis framework that is much different from the typical IDS you may know.