update lists
This commit is contained in:
@@ -1,4 +1,4 @@
|
||||
[38;5;12m [39m[38;2;255;187;0m[1m[4mAwesome Suricata [0m[38;5;14m[1m[4m![0m[38;2;255;187;0m[1m[4mAwesome[0m[38;5;14m[1m[4m (https://awesome.re/badge-flat2.svg)[0m[38;2;255;187;0m[1m[4m (https://awesome.re)[0m
|
||||
[38;5;12m [39m[38;2;255;187;0m[1m[4mAwesome Suricata [0m[38;5;14m[1m[4m![0m[38;2;255;187;0m[1m[4mAwesome[0m[38;5;14m[1m[4m (https://awesome.re/badge-flat2.svg)[0m[38;2;255;187;0m[1m[4m (https://awesome.re)[0m
|
||||
|
||||
[38;5;12m (https://suricata.io)[39m
|
||||
|
||||
@@ -18,6 +18,7 @@
|
||||
[38;5;12m- [39m[38;5;14m[1mAnalysis Tools[0m[38;5;12m (#analysis-tools)[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mRule Sets[0m[38;5;12m (#rule-sets)[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mRule/Security Content Management and Handling[0m[38;5;12m (#rulesecurity-content-management-and-handling)[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mPlugins and Extensions[0m[38;5;12m (#plugins-and-extensions)[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mSystems Using Suricata[0m[38;5;12m (#systems-using-suricata)[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mTraining[0m[38;5;12m (#training)[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mSimulation and Testing[0m[38;5;12m (#simulation-and-testing)[39m
|
||||
@@ -53,6 +54,7 @@
|
||||
[38;5;12m- [39m[38;5;14m[1mInfluxDB Suricata Input Plugin[0m[38;5;12m (https://github.com/influxdata/telegraf/tree/master/plugins/inputs/suricata) - Input Plugin for Telegraf to collect and forward Suricata [39m[48;5;235m[38;5;249mstats[49m[39m[38;5;12m logs (included out of the box in recent Telegraf releases).[39m
|
||||
[38;5;12m- [39m[38;5;14m[1msuricata_exporter[0m[38;5;12m (https://github.com/corelight/suricata_exporter) - Simple Prometheus exporter written in Go exporting stats metrics scraped from Suricata socket.[39m
|
||||
|
||||
|
||||
[38;2;255;187;0m[4mProgramming Libraries and Toolkits[0m
|
||||
|
||||
[38;5;12m- [39m[38;5;14m[1mrust-suricatax-rule-parser[0m[38;5;12m (https://github.com/jasonish/rust-suricatax-rule-parser) - Experimental Suricata Rule Parser in Rust.[39m
|
||||
@@ -73,18 +75,20 @@
|
||||
|
||||
[38;2;255;187;0m[4mDevelopment Tools[0m
|
||||
|
||||
[38;5;12m-[39m[38;5;12m [39m[38;5;14m[1mSuricata[0m[38;5;14m[1m [0m[38;5;14m[1mLanguage[0m[38;5;14m[1m [0m[38;5;14m[1mServer[0m[38;5;12m [39m[38;5;12m(https://github.com/StamusNetworks/suricata-language-server)[39m[38;5;12m [39m[38;5;12m-[39m[38;5;12m [39m[38;5;12mSuricata[39m[38;5;12m [39m[38;5;12mLanguage[39m[38;5;12m [39m[38;5;12mServer[39m[38;5;12m [39m[38;5;12mis[39m[38;5;12m [39m[38;5;12man[39m[38;5;12m [39m[38;5;12mimplementation[39m[38;5;12m [39m[38;5;12mof[39m[38;5;12m [39m[38;5;12mthe[39m[38;5;12m [39m[38;5;12mLanguage[39m[38;5;12m [39m[38;5;12mServer[39m[38;5;12m [39m[38;5;12mProtocol[39m[38;5;12m [39m[38;5;12mfor[39m[38;5;12m [39m[38;5;12mSuricata[39m[38;5;12m [39m[38;5;12msignatures.[39m[38;5;12m [39m[38;5;12mIt[39m[38;5;12m [39m[38;5;12madds[39m[38;5;12m [39m[38;5;12msyntax[39m[38;5;12m [39m[38;5;12mcheck,[39m[38;5;12m [39m[38;5;12mhints[39m[38;5;12m [39m[38;5;12mand[39m[38;5;12m [39m
|
||||
[38;5;12mauto-completion[39m[38;5;12m [39m[38;5;12mto[39m[38;5;12m [39m[38;5;12myour[39m[38;5;12m [39m[38;5;12mpreferred[39m[38;5;12m [39m[38;5;12meditor[39m[38;5;12m [39m[38;5;12monce[39m[38;5;12m [39m[38;5;12mit[39m[38;5;12m [39m[38;5;12mis[39m[38;5;12m [39m[38;5;12mconfigured.[39m
|
||||
[38;5;12m-[39m[38;5;12m [39m[38;5;14m[1mSuricata[0m[38;5;14m[1m [0m[38;5;14m[1mLanguage[0m[38;5;14m[1m [0m[38;5;14m[1mServer[0m[38;5;12m [39m[38;5;12m(https://github.com/StamusNetworks/suricata-language-server)[39m[38;5;12m [39m[38;5;12m-[39m[38;5;12m [39m[38;5;12mSuricata[39m[38;5;12m [39m[38;5;12mLanguage[39m[38;5;12m [39m[38;5;12mServer[39m[38;5;12m [39m[38;5;12mis[39m[38;5;12m [39m[38;5;12man[39m[38;5;12m [39m[38;5;12mimplementation[39m[38;5;12m [39m[38;5;12mof[39m[38;5;12m [39m[38;5;12mthe[39m[38;5;12m [39m[38;5;12mLanguage[39m[38;5;12m [39m[38;5;12mServer[39m[38;5;12m [39m[38;5;12mProtocol[39m[38;5;12m [39m[38;5;12mfor[39m[38;5;12m [39m[38;5;12mSuricata[39m[38;5;12m [39m[38;5;12msignatures.[39m[38;5;12m [39m[38;5;12mIt[39m[38;5;12m [39m[38;5;12madds[39m[38;5;12m [39m[38;5;12msyntax[39m[38;5;12m [39m[38;5;12mcheck,[39m[38;5;12m [39m[38;5;12mhints[39m[38;5;12m [39m[38;5;12mand[39m[38;5;12m [39m[38;5;12mauto-completion[39m[38;5;12m [39m[38;5;12mto[39m[38;5;12m [39m
|
||||
[38;5;12myour[39m[38;5;12m [39m[38;5;12mpreferred[39m[38;5;12m [39m[38;5;12meditor[39m[38;5;12m [39m[38;5;12monce[39m[38;5;12m [39m[38;5;12mit[39m[38;5;12m [39m[38;5;12mis[39m[38;5;12m [39m[38;5;12mconfigured.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1msuricata-ls-vscode[0m[38;5;12m (https://github.com/StamusNetworks/suricata-ls-vscode) - Suricata IntelliSense Extension using the Suricata Language Server.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1msuricata-highlight-vscode[0m[38;5;12m (https://github.com/dgenzer/suricata-highlight-vscode) - Suricata Rules Support for Visual Studio Code (syntax highlighting, etc).[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mSublimeSuricata[0m[38;5;12m (https://github.com/ozuriexv/SublimeSuricata) - Basic Suricata syntax highlighter for Sublime Text.[39m
|
||||
|
||||
[38;5;12m-[39m[38;5;12m [39m[38;5;14m[1mSuricata-Check[0m[38;5;12m [39m[38;5;12m(https://suricata-check.teuwen.net/readme.html)[39m[38;5;12m [39m[38;5;12m-[39m[38;5;12m [39m[38;5;12msuricata-check[39m[38;5;12m [39m[38;5;12mis[39m[38;5;12m [39m[38;5;12ma[39m[38;5;12m [39m[38;5;12mcommand-line[39m[38;5;12m [39m[38;5;12mutility[39m[38;5;12m [39m[38;5;12mto[39m[38;5;12m [39m[38;5;12mprovide[39m[38;5;12m [39m[38;5;12mfeedback[39m[38;5;12m [39m[38;5;12mon[39m[38;5;12m [39m[38;5;12mSuricata[39m[38;5;12m [39m[38;5;12mrules.[39m[38;5;12m [39m[38;5;12mIt[39m[38;5;12m [39m[38;5;12mcan[39m[38;5;12m [39m[38;5;12mdetect[39m[38;5;12m [39m[38;5;12missues[39m[38;5;12m [39m[38;5;12msuch[39m[38;5;12m [39m[38;5;12mas[39m[38;5;12m [39m[38;5;12mcovering[39m[38;5;12m [39m[38;5;12msyntax[39m[38;5;12m [39m[38;5;12mvalidity,[39m[38;5;12m [39m[38;5;12minterpretability,[39m[38;5;12m [39m[38;5;12mrule[39m[38;5;12m [39m[38;5;12mspecificity,[39m[38;5;12m [39m[38;5;12mrule[39m[38;5;12m [39m
|
||||
[38;5;12mcoverage,[39m[38;5;12m [39m[38;5;12mand[39m[38;5;12m [39m[38;5;12mefficiency.[39m
|
||||
|
||||
[38;2;255;187;0m[4mDocumentation and Guides[0m
|
||||
|
||||
[38;5;12m- [39m[38;5;14m[1mSEPTun[0m[38;5;12m (https://github.com/pevma/SEPTun) - Suricata Extreme Performance Tuning guide.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mSEPTun-Mark-II[0m[38;5;12m (https://github.com/pevma/SEPTun-Mark-II) - Suricata Extreme Performance Tuning guide - Mark II.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1msuricata-4-analysts[0m[38;5;12m (https://github.com/StamusNetworks/suricata-4-analysts) - The Security Analyst's Guide to Suricata.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mSuricata Community Style Guide[0m[38;5;12m (https://github.com/sidallocation/suricata-style-guide) - A collaborative document to collect style guidelines from the community of rule writers.[39m
|
||||
|
||||
|
||||
[38;2;255;187;0m[4mAnalysis Tools[0m
|
||||
@@ -109,6 +113,8 @@
|
||||
[38;5;12m- [39m[38;5;14m[1m3CORESec NIDS - Lateral Movement[0m[38;5;12m (https://dtection.io/ruleset/3cs_lateral) - Suricata ruleset focusing on lateral movement techniques (paid).[39m
|
||||
[38;5;12m- [39m[38;5;14m[1m3CORESec NIDS - Sinkholes[0m[38;5;12m (https://dtection.io/ruleset/3cs_sinkholes) - Suricata ruleset focused on a curated list of public malware sinkholes (free).[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mPAW Patrules[0m[38;5;12m (https://pawpatrules.fr) - Another free (CC BY-NC-SA) collection of rules for the Suricata engine.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mopnsense-suricata-nmaps[0m[38;5;12m (https://github.com/aleksibovellan/opnsense-suricata-nmaps) - OPNSense's Suricata IDS/IPS Detection Rules Against NMAP Scans.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mAntiphishing[0m[38;5;12m (https://github.com/julioliraup/Antiphishing) - Suricata rules and datasets to detect phishing attacks.[39m
|
||||
|
||||
|
||||
[38;2;255;187;0m[4mRule/Security Content Management and Handling[0m
|
||||
@@ -121,8 +127,12 @@
|
||||
[38;5;12m- [39m[38;5;14m[1msurify-cli[0m[38;5;12m (https://github.com/dgenzer/surify-cli) - Generate suricata-rules from collection of IOCs (JSON, CSV or flags) based on your suricata template.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1msuricata-prettifier[0m[38;5;12m (https://github.com/theY4Kman/suricata-prettifier) - Command-line tool to format and syntax highlight Suricata rules.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mOTX-Suricata[0m[38;5;12m (https://github.com/AlienVault-OTX/OTX-Suricata) - Create rules and configuration for Suricata to alert on indicators from an OTX account.[39m
|
||||
[38;5;12m-[39m[38;5;12m [39m[38;5;14m[1mAristotle[0m[38;5;12m [39m[38;5;12m(https://github.com/secureworks/aristotle)[39m[38;5;12m [39m[38;5;12m-[39m[38;5;12m [39m[38;5;12mSimple[39m[38;5;12m [39m[38;5;12mPython[39m[38;5;12m [39m[38;5;12mprogram[39m[38;5;12m [39m[38;5;12mthat[39m[38;5;12m [39m[38;5;12mallows[39m[38;5;12m [39m[38;5;12mfor[39m[38;5;12m [39m[38;5;12mthe[39m[38;5;12m [39m[38;5;12mfiltering[39m[38;5;12m [39m[38;5;12mand[39m[38;5;12m [39m[38;5;12mmodifying[39m[38;5;12m [39m[38;5;12mof[39m[38;5;12m [39m[38;5;12mSuricata[39m[38;5;12m [39m[38;5;12mand[39m[38;5;12m [39m[38;5;12mSnort[39m[38;5;12m [39m[38;5;12mrulesets[39m[38;5;12m [39m[38;5;12mbased[39m[38;5;12m [39m[38;5;12mon[39m[38;5;12m [39m[38;5;12minterpreted[39m[38;5;12m [39m[38;5;12mkey-value[39m[38;5;12m [39m[38;5;12mpairs[39m[38;5;12m [39m[38;5;12mpresent[39m[38;5;12m [39m[38;5;12min[39m[38;5;12m [39m[38;5;12mthe[39m[38;5;12m [39m[38;5;12mmetadata[39m[38;5;12m [39m[38;5;12mkeyword[39m[38;5;12m [39m[38;5;12mwithin[39m[38;5;12m [39m[38;5;12meach[39m[38;5;12m [39m
|
||||
[38;5;12mrule.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mAristotle[0m[38;5;12m (https://github.com/secureworks/aristotle) - Simple Python program that allows for the filtering and modifying of Suricata and Snort rulesets based on interpreted key-value pairs present in the metadata keyword within each rule.[39m
|
||||
|
||||
|
||||
[38;2;255;187;0m[4mPlugins and Extensions[0m
|
||||
|
||||
[38;5;12m- [39m[38;5;14m[1msuricata-zabbix[0m[38;5;12m (https://github.com/catenacyber/suricata-zabbix) - Zabbix application layer plugin for Suricata.[39m
|
||||
|
||||
|
||||
[38;2;255;187;0m[4mSystems Using Suricata[0m
|
||||
@@ -154,6 +164,8 @@
|
||||
[38;2;255;187;0m[4mMisc[0m
|
||||
|
||||
[38;5;12m- [39m[38;5;14m[1mSuriwire[0m[38;5;12m (https://github.com/regit/suriwire) - Wireshark plugin to display Suricata analysis info.[39m
|
||||
[38;5;12m-[39m[38;5;12m [39m[38;5;14m[1mbash_cata[0m[38;5;12m [39m[38;5;12m(https://github.com/isMTv/bash_cata)[39m[38;5;12m [39m[38;5;12m-[39m[38;5;12m [39m[38;5;12mA[39m[38;5;12m [39m[38;5;12msimple[39m[38;5;12m [39m[38;5;12mscript[39m[38;5;12m [39m[38;5;12mthat[39m[38;5;12m [39m[38;5;12mprocesses[39m[38;5;12m [39m[38;5;12mthe[39m[38;5;12m [39m[38;5;12mgenerated[39m[38;5;12m [39m[38;5;12mSuricata[39m[38;5;12m [39m[38;5;12meve-log[39m[38;5;12m [39m[38;5;12min[39m[38;5;12m [39m[38;5;12mreal[39m[38;5;12m [39m[38;5;12mtime[39m[38;5;12m [39m[38;5;12mand,[39m[38;5;12m [39m[38;5;12mbased[39m[38;5;12m [39m[38;5;12mon[39m[38;5;12m [39m[38;5;12malerts,[39m[38;5;12m [39m[38;5;12madds[39m[38;5;12m [39m[38;5;12man[39m[38;5;12m [39m[38;5;12mip-address[39m[38;5;12m [39m[38;5;12mto[39m[38;5;12m [39m[38;5;12mthe[39m[38;5;12m [39m[38;5;12mMikroTik[39m[38;5;12m [39m[38;5;12mAddress[39m[38;5;12m [39m[38;5;12mLists[39m[38;5;12m [39m[38;5;12mfor[39m[38;5;12m [39m[38;5;12ma[39m[38;5;12m [39m[38;5;12mspecified[39m[38;5;12m [39m[38;5;12mtime[39m[38;5;12m [39m[38;5;12mfor[39m[38;5;12m [39m[38;5;12msubsequent[39m[38;5;12m [39m
|
||||
[38;5;12mblocking.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mbash_cata[0m[38;5;12m (https://github.com/isMTv/bash_cata) - A simple script that processes the generated Suricata eve-log in real time and, based on alerts, adds an ip-address to the MikroTik Address Lists for a specified time for subsequent blocking.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1msuriGUI[0m[38;5;12m (https://github.com/control-owl/suriGUI) - GUI for Suricata + Qubes OS.[39m
|
||||
[38;5;12m- [39m[38;5;14m[1mSuriGuard[0m[38;5;12m (https://github.com/SEc-123/SuriGuard1) - Web-based management system for Suricata IDS/IPS, featuring advanced analytics and visualization capabilities.[39m
|
||||
|
||||
[38;5;12msuricata Github: https://github.com/satta/awesome-suricata[39m
|
||||
|
||||
Reference in New Issue
Block a user