
pySigma
Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)

Automatically generated Sysmon parser for Azure Sentinel

DShield Sensor Log Collection with ELK

A Zeek OpenVPN protocol analyzer plugin.

Parse citrix netscaler logs to check for signs of CVE-2023-4966 exploitation

ETW and WPP tracing tool for security research. Subscribes to multiple providers, auto-parses events to JSON, and supports advanced filtering,…

Parse, filter, and visualize Suricata eve.json logs with CLI tools for alerts, flows, DNS, and payloads. Includes a tutorial for learning Suricata…

Parses Windows .evtx logs to identify remote connections and public IPs by analyzing EventIDs related to remote logins and sessions.

This is a repo for fetching Applocker event log by parsing the win-event log

Bro analyzer that detects Google's QUIC protocol