Active Countermeasures
Active Countermeasures
passer
Passive service locator, a python sniffer that identifies servers, clients, names and much more
rita
Real Intelligence Threat Analytics (RITA) is a framework for detecting command and control communication through network traffic analysis.
BeaKer
Beacon Kibana Executable Report. Aggregates Sysmon Network Events With Elasticsearch and Kibana
docker-zeek
Run zeek with zeekctl in docker
espy
Endpoint detection for remote hosts for consumption by RITA and Elasticsearch
pcap-stats
Learn about a network from a pcap file or reading from an interface
threat-hunting-labs
Collection of walkthroughs on various threat hunting techniques