
zeek-quic
Bro analyzer that detects Google's QUIC protocol
Log parsing, SIEM, centralized logging, forensic timeline, and security event correlation tools.

Bro analyzer that detects Google's QUIC protocol

A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further…


Chronicle parser for CORELIGHT and related information.

Corelight Dashboards and Parsers for Sentinel One Singularity

This package extends the Intel package to log more fields

A Prometheus Exporter for Suricata


A Zeek OpenVPN protocol analyzer, based on Spicy.

Reproducible SOC lab for CVE-2024-4577 detection and response

End-to-end SOC incident analysis and threat hunting playbook targeting Microsoft SharePoint privilege escalation (CVE-2023-29375) using SIEM logs,…

Mapping Corelight or Zeek data to Elastic Common Schema logs

The easiest, and most secure way to access and protect all of your infrastructure.

Mapping Corelight or Zeek data to Elastic Common Schema fields

Corelight or Zeek Elastic Common Schema Templates

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

A tool to subscribe to receive all standard Android broadcasts on your Android device.

macos-collector - Automated Collection of macOS Forensic Artifacts for DFIR