espy

Network log collector

A system for collecting and processing network connection logs from Microsoft Sysmon in Elastic ECS format

Endpoint detection for remote hosts for consumption by RITA and Elasticsearch

GitHub

66 stars
8 watching
16 forks
Language: Go
last commit: over 1 year ago

Related projects:

Repository Description Stars
toni-moreno/snmpcollector A tool to collect and store network device data in a time-series format 289
anssi-fr/dfir-o365rc A PowerShell module for collecting and analyzing logs from Microsoft 365 and Azure systems 249
activecm/beaker Aggregates Microsoft Sysmon network events with Elasticsearch and Kibana for threat hunting analysis 285
elodina/syslog-service A Go-based system for collecting and forwarding log data 0
pablolec/neoss A tool that displays detailed statistics of active network connections with a user-friendly terminal interface. 153
alexlynd/esp8266-wardriving Scripts and tools for collecting and visualizing WiFi data using an ESP8266 microcontroller 155
oxalide/vsphere-influxdb-go A tool that collects performance metrics from VMware vCenter and ESXi servers and sends them to an InfluxDB database. 216
marty90/netlytics A framework for performing advanced analytics on network logs using Hadoop and Apache Spark 9
azure/networkmonitoring Tools for monitoring network performance and availability from Azure. 104
chris-barry/i2spy A tool to collect and centralize I2P node statistics. 14
sccn/labstreaminglayer A unified platform for collecting and viewing time-series data from various devices in research experiments. 556
mac4n6/apollo A tool for gathering and analyzing device data from various platforms. 564
mdecrevoisier/splunk-input-windows-baseline Provides an advanced Splunk configuration for collecting Windows log data relevant to threat detection, incident response, and forensic analysis. 81
danielmartensson/opensourcelogger Software for collecting and analyzing measurement data from industrial equipment. 16
hypnoze57/sharphound4cobalt A tool for collecting and reporting network activity data to Cobalt Strike. 46