Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level semantic logs. It functions as an application protocol analyzer and network intrusion detection system designed to extract meaning from network traffic and monitor for malicious activity. The system focuses on archiving network activity and maintaining historical records of application-layer state for forensic investigation and auditing. It utilizes a combination of modular protocol analyzers and customizable detection policies to perform deep semantic analysis of numerous app
AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of third-party hacking and security utilities from a single command interface. It functions as a centralized hub for network analysis, open source intelligence, penetration testing, and social engineering tools. The project provides specialized frameworks for gathering open source intelligence and searching for user profiles across social platforms. It includes toolkits for network reconnaissance, vulnerability scanning, and the execution of security exploits, as well as a social eng
FakeNet-NG - Next Generation Dynamic Network Analysis Tool
Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.
integrating bro into yara
The main features of hempnall/broyara are: Network Analysis.
Open-source alternatives to hempnall/broyara include: zeek/zeek — Zeek is a network analysis framework and security monitoring tool that transforms raw network packets into high-level… mishakorzik/allhackingtools — AllHackingTools is a security tool orchestrator and suite designed to install, update, and manage a wide array of… fireeye/flare-fakenet-ng — FakeNet-NG - Next Generation Dynamic Network Analysis Tool. jbremer/httpreplay — Replay HTTP and HTTPS requests from a PCAP based on TLS Master Secrets. jpr5/ngrep — ngrep is like GNU grep applied to the network layer. It's a PCAP-based tool that allows you to specify an extended… idaholab/malcolm — Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP…