Skip to content
Change the repository type filter

All

    Repositories list

    • rita

      Public
      Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
      Go
      GNU General Public License v3.0
      58548166Updated Apr 2, 2026Apr 2, 2026
    • Run zeek with zeekctl in docker
      Go
      GNU General Public License v3.0
      226374Updated Mar 27, 2026Mar 27, 2026
    • Zeek
      GNU General Public License v3.0
      41710Updated Mar 24, 2026Mar 24, 2026
    • espy

      Public
      Endpoint detection for remote hosts for consumption by RITA and Elasticsearch
      Go
      GNU General Public License v3.0
      208070Updated Mar 19, 2026Mar 19, 2026
    • BeaKer

      Public
      Beacon Kibana Executable Report. Aggregates Sysmon Network Events With Elasticsearch and Kibana
      Shell
      GNU General Public License v3.0
      4430232Updated Mar 19, 2026Mar 19, 2026
    • This script ships logs from Zeek to AC-Hunter
      Shell
      3733Updated Mar 19, 2026Mar 19, 2026
    • ACH-Zeek

      Public
      Zeek installer packaged with AC-Hunter
      Shell
      0000Updated Mar 19, 2026Mar 19, 2026
    • passer

      Public
      Passive service locator, a python sniffer that identifies servers, clients, names and much more
      Python
      GNU General Public License v3.0
      5426202Updated Feb 9, 2026Feb 9, 2026
    • Json file that holds TCP signatures for passive OS fingerprinting
      Python
      GNU General Public License v3.0
      1100Updated Feb 9, 2026Feb 9, 2026
    • shell-lib

      Public archive
      Shell Scripts Used Across ActiveCM Projects
      Shell
      BSD 3-Clause "New" or "Revised" License
      3431Updated Feb 5, 2026Feb 5, 2026
    • Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
      Go
      GNU General Public License v3.0
      3532.5k814Updated Jan 12, 2026Jan 12, 2026
    • Tools for working with Zeek logs
      Shell
      GNU General Public License v3.0
      0100Updated Jun 19, 2025Jun 19, 2025
    • zcutter

      Public
      Extracts fields from zeek logs, compatible with zeek-cut
      Python
      GNU General Public License v3.0
      62700Updated Jul 10, 2024Jul 10, 2024
    • Tools for working with the safelist (formerly whitelist)
      Go
      GNU General Public License v3.0
      4511Updated Apr 11, 2024Apr 11, 2024
    • Learn about a network from a pcap file or reading from an interface
      Python
      GNU General Public License v3.0
      52910Updated Apr 6, 2024Apr 6, 2024
    • Template for building a packet sniffer
      Python
      GNU General Public License v3.0
      51500Updated Mar 25, 2024Mar 25, 2024
    • Tools for simulating threats
      Python
      GNU General Public License v3.0
      3720300Updated Oct 27, 2023Oct 27, 2023
    • JSON TCP stream importer for RITA and AC-Hunter
      Python
      GNU General Public License v3.0
      2100Updated Sep 8, 2023Sep 8, 2023
    • rita-bl

      Public archive
      Real Intelligence Threat Analytics -- Blacklist Database
      Go
      GNU General Public License v3.0
      81020Updated Jul 12, 2023Jul 12, 2023
    • smudge

      Public
      Passive OS detection based on SYN packets without Transmitting any Data
      Python
      GNU General Public License v3.0
      95050Updated Mar 29, 2023Mar 29, 2023
    • zeekcfg

      Public
      A node.cfg generator for zeekctl
      Go
      MIT License
      4730Updated Nov 11, 2022Nov 11, 2022
    • Delete Zeek log files until disk usage is under a given threshold
      Shell
      MIT License
      1310Updated Jul 1, 2022Jul 1, 2022
    • An open source list of ASNs known to belong to cloud, managed hosting, and colo facilities.
      117200Updated Jun 22, 2022Jun 22, 2022
    • Support files and tools for pcap analysis and packet capture
      GNU General Public License v3.0
      3300Updated Mar 1, 2022Mar 1, 2022
    • Identifies certificate problems from Zeek ssl log files
      Shell
      GNU General Public License v3.0
      0400Updated Jan 19, 2022Jan 19, 2022
    • mgosec

      Public archive
      A Small Helper Library For Securing MongoDB Connections with Golang
      Go
      MIT License
      0410Updated Dec 1, 2021Dec 1, 2021
    • Github Action to get release information based on a tag
      JavaScript
      MIT License
      43000Updated Oct 19, 2021Oct 19, 2021
    • Collection of walkthroughs on various threat hunting techniques
      HTML
      GNU General Public License v3.0
      197700Updated Aug 3, 2020Aug 3, 2020
    • bro-install

      Public archive
      An Installation Script for Bro IDS on Debian Based Systems
      Shell
      72000Updated Jun 25, 2020Jun 25, 2020
    • A support library and set of scripts to simplify installing software on the Raspberry Pi/Raspbian
      Shell
      GNU General Public License v3.0
      2500Updated Feb 4, 2020Feb 4, 2020
    ProTip! When viewing an organization's repositories, you can use the props. filter to filter by custom property.