
synacktiv-rules
Öffentliches Repository mit Sigma- und YARA-Regeln, erstellt von Synacktiv

Öffentliches Repository mit Sigma- und YARA-Regeln, erstellt von Synacktiv

ShellShock-Angriffs- und Exploit-Detektor für Bro.

Erkennung des Manjusaka C2-Frameworks

Ein offener Standard zum Hashen von Netzwerkflüssen in Identifikatoren, auch bekannt als „Community IDs“.

Corelight-Ansible-Roles are a collection of Ansible Roles and playbooks that install, configure, run and manage a variety of Corelight, Suricata and…

Corelight-App für CrowdStrike LogScale und Next-Gen SIEM


DNS Dashboard zum Aufspüren und Identifizieren von Beaconing

Elastic-Version der SOC-Prime-Watcher-Regeln

Eine Go-Bibliothek zur Verwendung der Websocket-API von Zeek Broker.

Detect HTTP stalling attacks like slowloris with Bro

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…


Zeek-Paket zur Erkennung von PetitPotam-NTLM-Relay-Angriffen über EFS DCERPC auf unverschlüsseltem SMB, das zwischen erfolgreichen und erfolglosen…

Automatisierte Playbooks zur Reaktion auf Sicherheitsvorfälle für Splunk Phantom, die Zeek-Protokolle, DNS-Analysen und VirusTotal-Bedrohungsdaten…

Ein Zeek-Paket zur Erkennung des Command-and-Control-Netzwerkverkehrs (C2) der Pingback-Malware über den ICMP-Tunnel.

Corelight@Home-Skript