Skip to content
Change the repository type filter

All

    Repositories list

    • rita

      Public
      Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
      Go
      43437246Updated Dec 13, 2025Dec 13, 2025
    • BeaKer

      Public
      Beacon Kibana Executable Report. Aggregates Sysmon Network Events With Elasticsearch and Kibana
      Shell
      4229932Updated Nov 26, 2025Nov 26, 2025
    • espy

      Public
      Endpoint detection for remote hosts for consumption by RITA and Elasticsearch
      Go
      188070Updated Oct 14, 2025Oct 14, 2025
    • zeek-log-tools

      Public
      Tools for working with Zeek logs
      Shell
      0100Updated Jun 19, 2025Jun 19, 2025
    • zeek-log-transport

      Public
      This script ships logs from Zeek to AC-Hunter
      Shell
      2633Updated Apr 1, 2025Apr 1, 2025
    • Run zeek with zeekctl in docker
      Shell
      215974Updated Sep 12, 2024Sep 12, 2024
    • zeek-open-connections

      Public
      Zeek
      41510Updated Aug 15, 2024Aug 15, 2024
    • rita-legacy

      Public
      Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
      Go
      3592.5k8110Updated Jul 10, 2024Jul 10, 2024
    • zcutter

      Public
      Extracts fields from zeek logs, compatible with zeek-cut
      Python
      32500Updated Jul 10, 2024Jul 10, 2024
    • shell-lib

      Public
      Shell Scripts Used Across ActiveCM Projects
      Shell
      2441Updated Apr 30, 2024Apr 30, 2024
    • safelist-tools

      Public
      Tools for working with the safelist (formerly whitelist)
      Go
      4511Updated Apr 11, 2024Apr 11, 2024
    • Learn about a network from a pcap file or reading from an interface
      Python
      42910Updated Apr 6, 2024Apr 6, 2024
    • active-dns-lookup

      Public
      Lookup hostnames via dns
      Python
      0000Updated Apr 6, 2024Apr 6, 2024
    • Template for building a packet sniffer
      Python
      41500Updated Mar 25, 2024Mar 25, 2024
    • threat-tools

      Public
      Tools for simulating threats
      Python
      3319900Updated Oct 27, 2023Oct 27, 2023
    • save_json_stream

      Public
      JSON TCP stream importer for RITA and AC-Hunter
      Python
      1100Updated Sep 8, 2023Sep 8, 2023
    • rita-bl

      Public archive
      Real Intelligence Threat Analytics -- Blacklist Database
      Go
      81020Updated Jul 12, 2023Jul 12, 2023
    • ACH-Zeek

      Public
      Zeek installer packaged with AC-Hunter
      Shell
      0100Updated May 25, 2023May 25, 2023
    • smudge

      Public
      Passive OS detection based on SYN packets without Transmitting any Data
      Python
      64950Updated Mar 29, 2023Mar 29, 2023
    • passer

      Public
      Passive service locator, a python sniffer that identifies servers, clients, names and much more
      Python
      5125602Updated Feb 16, 2023Feb 16, 2023
    • db-lib

      Public
      Python database access library
      Python
      0000Updated Jan 3, 2023Jan 3, 2023
    • Json file that holds TCP signatures for passive OS fingerprinting
      Python
      1100Updated Dec 13, 2022Dec 13, 2022
    • Open source endpoint agent providing host information to Zeek. [v2]
      C++
      8000Updated Nov 29, 2022Nov 29, 2022
    • zeekcfg

      Public
      A node.cfg generator for zeekctl
      Go
      4730Updated Nov 11, 2022Nov 11, 2022
    • Delete Zeek log files until disk usage is under a given threshold
      Shell
      1310Updated Jul 1, 2022Jul 1, 2022
    • An open source list of ASNs known to belong to cloud, managed hosting, and colo facilities.
      114200Updated Jun 22, 2022Jun 22, 2022
    • Support files and tools for pcap analysis and packet capture
      2300Updated Mar 1, 2022Mar 1, 2022
    • Identifies certificate problems from Zeek ssl log files
      Shell
      0400Updated Jan 19, 2022Jan 19, 2022
    • mgosec

      Public archive
      A Small Helper Library For Securing MongoDB Connections with Golang
      Go
      0410Updated Dec 1, 2021Dec 1, 2021
    • Github Action to get release information based on a tag
      JavaScript
      43000Updated Oct 19, 2021Oct 19, 2021