
C2-detection-manjusaka
Detection of Manjusaka C2 framework
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Detection of Manjusaka C2 framework

An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

A Bro package to identify connections that are bursting (lots of data and transferring quickly).

Corelight app for CrowdStrike LogScale and Next-Gen SIEM


Elastic version of SOC prime watcher rules

Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and…

Add POST body excerpt to Bro's HTTP log


Corelight@Home script

Top DNS Measurement for Bro

Zeek Log Cheatsheets

Zeek support for Community ID flow hashing.


Enrich the conn.log with EDR data

Zeek package for tracking long connections to report them before they have completed.

A Zeek OpenVPN protocol analyzer plugin.

Bro analyzer that detects Google's QUIC protocol