awesome-suricata

Suricata toolkit

A curated collection of tools and libraries supporting the Suricata intrusion detection/prevention system

A curated list of awesome things related to Suricata

GitHub

139 stars
6 watching
11 forks
last commit: almost 2 years ago
Linked from 1 awesome list

awesomeawesome-listidsipslistsnsmsuricata

Awesome Suricata / Input Tools

PacketStreamer1,891about 2 years agoDistributed tcpdump for cloud native environments

Awesome Suricata / Output Tools

suricata-kafka-output14almost 5 years agoSuricata Eve Kafka Output Plugin for Suricata 6
suricata-redis-output7over 4 years agoSuricata Eve Redis Output Plugin for Suricata 7
Meer28over 3 years agoMeer is a "spooler" for Suricata / Sagan
FEVER51about 2 years agoFast, extensible, versatile event router for Suricata's EVE-JSON format
Suricata-Logstash-Templates80over 10 years agoTemplates for Kibana/Logstash to use with Suricata IDPS
Lilith1almost 4 years agoReads EVE files into SQL as well as search stored data

Awesome Suricata / Operations, Monitoring and Troubleshooting

slinkwatch11almost 7 years agoAutomatic enumeration and maintenance of Suricata monitoring interfaces
suri-stats28almost 11 years agoA tool to work on suricata file
Mauerspecht3about 7 years agoSimple Probing Tool for Corporate Walled Garden Networks
ansible-suricata1about 8 years agoSuricata Ansible role (slightly outdated)
MassDeploySuricata9almost 12 years agoMass deploy and update Suricata IDPS using Ansible IT automation platform
docker-suricata269almost 2 years agoSuricata Docker image
Suricata-Monitoring0over 2 years agoLibreNMS JSON / Nagios monitor for Suricata stats
Terraform Module for Suricata9about 4 years agoTerraform module to setup Google Cloud packet mirroring and send packets to Suricata
InfluxDB Suricata Input Plugin14,974almost 2 years agoInput Plugin for Telegraf to collect and forward Suricata logs (included out of the box in recent Telegraf releases)
suricata_exporter19almost 2 years agoSimple Prometheus exporter written in Go exporting stats metrics scraped from Suricata socket

Awesome Suricata / Programming Libraries and Toolkits

rust-suricatax-rule-parser9over 2 years agoExperimental Suricata Rule Parser in Rust
go-suricata12about 6 years agoGo Client for Suricata (Interacting via Socket)
gonids180almost 4 years agoGo library to parse intrusion detection rules for engines like Snort and Suricata
surevego14over 7 years agoSuricata EVE-JSON parser in Go
suricataparser29over 2 years agoPure python parser for Snort/Suricata rules
py-idstools279almost 3 years agoSnort and Suricata Rule and Event Utilities in Python (Including a Rule Update Tool)

Awesome Suricata / Dashboards and Templates

KTS33about 10 years agoKibana 4 Templates for Suricata IDPS Threat Hunting
KTS543over 8 years agoKibana 5 Templates for Suricata IDPS Threat Hunting
KTS624over 7 years agoKibana 6 Templates for Suricata IDPS Threat Hunting
KTS740almost 4 years agoKibana 7 Templates for Suricata IDPS Threat Hunting

Awesome Suricata / Development Tools

Suricata Language Server66almost 2 years agoSuricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and auto-completion to your preferred editor once it is configured
suricata-ls-vscode3over 4 years agoSuricata IntelliSense Extension using the Suricata Language Server
suricata-highlight-vscode12over 4 years agoSuricata Rules Support for Visual Studio Code (syntax highlighting, etc)
SublimeSuricata35almost 3 years agoBasic Suricata syntax highlighter for Sublime Text

Awesome Suricata / Documentation and Guides

SEPTun204over 8 years agoSuricata Extreme Performance Tuning guide
SEPTun-Mark-II114over 8 years agoSuricata Extreme Performance Tuning guide - Mark II
suricata-4-analysts53over 2 years agoThe Security Analyst's Guide to Suricata
Suricata Community Style Guide7over 2 years agoA collaborative document to collect style guidelines from the community of rule writers

Awesome Suricata / Analysis Tools

Suricata Analytics29almost 2 years agoVarious resources that are useful when interacting with Suricata data
Malcolm2,001almost 2 years agoA powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts
Evebox433almost 2 years agoWeb Based Event Viewer (GUI) for Suricata EVE Events in Elastic Search

Awesome Suricata / Rule Sets

nids-rule-library22about 3 years agoCollection of various open-source and commercial rulesets
Stamus Lateral Movement Detection RulesSuricata ruleset to detect lateral movement
QuadrantSec Suricata Rules5over 3 years agoQuadrantSec Suricata rules
Cluster25/detection13over 2 years agoCluster25's detection rules

Awesome Suricata / Rule Sets / Networkforensic.dk (NF) rules sets:

NF IDS rules
NF SCADA IDS Rules
NF Scanners IDS Rules

Awesome Suricata / Rule Sets

Quantum Insert detection for Suricata212over 7 years agoSuricata rules accompanying Fox-IT's QUANTUM 2015 blog/BroCon talk
Hunting rules154almost 2 years agoSuricata IDS alert rules for network anomaly detection from Travis Green
3CORESec NIDS - Lateral MovementSuricata ruleset focusing on lateral movement techniques (paid)
3CORESec NIDS - SinkholesSuricata ruleset focused on a curated list of public malware sinkholes (free)
PAW PatrulesAnother free (CC BY-NC-SA) collection of rules for the Suricata engine
opnsense-suricata-nmaps59over 2 years agoOPNSense's Suricata IDS/IPS Detection Rules Against NMAP Scans
Antiphishing3almost 2 years agoSuricata rules and datasets to detect phishing attacks

Awesome Suricata / Rule/Security Content Management and Handling

sidallocation.orgSid Allocation working group, list of SID ranges
Scirius636almost 2 years agoWeb application for Suricata ruleset management and threat hunting
IOCmite37almost 4 years agoTool to create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert
luaevilbit2almost 14 years agoAn Evil bit implementation in luajit for Suricata
LawmakerSuricata IDS rule and fleet management system
surify-cli3about 5 years agoGenerate suricata-rules from collection of IOCs (JSON, CSV or flags) based on your suricata template
suricata-prettifier13almost 7 years agoCommand-line tool to format and syntax highlight Suricata rules
OTX-Suricata107over 2 years agoCreate rules and configuration for Suricata to alert on indicators from an OTX account
Aristotle36almost 2 years agoSimple Python program that allows for the filtering and modifying of Suricata and Snort rulesets based on interpreted key-value pairs present in the metadata keyword within each rule

Awesome Suricata / Plugins and Extensions

suricata-zabbix1almost 2 years agoZabbix application layer plugin for Suricata

Awesome Suricata / Systems Using Suricata

SELKS1,492about 2 years agoA Suricata-based intrusion detection system/intrusion prevention system/network security monitoring distribution
Amsterdam184about 4 years agoDocker based Suricata, Elasticsearch, Logstash, Kibana, Scirius aka SELKS
pfSenseA free network firewall distribution, based on the FreeBSD operating system with a custom kernel and including third party free software packages for additional functionality
OPNsenseAn open source, easy-to-use and easy-to-build FreeBSD based firewall and routing platform

Awesome Suricata / Training

Experimental Suricata Training Environment6over 2 years agoExperimental Suricata Training Environment
CDMCS100over 2 years agoCyber Defence Monitoring Course: Rule-based Threat Detection

Awesome Suricata / Simulation and Testing

Leonidas535almost 2 years agoAutomated Attack Simulation in the Cloud, complete with detection use cases
speeve8over 2 years agoFast, probabilistic EVE-JSON generator for testing and benchmarking of EVE-consuming applications
Dalton460almost 2 years agoSuricata and Snort IDS rule and pcap testing system

Awesome Suricata / Data Sets

suricata-sample-data31over 7 years agoRepository of creating different example suricata data sets

Awesome Suricata / Misc

Suriwire92almost 5 years agoWireshark plugin to display Suricata analysis info
bash_cata9over 2 years agoA simple script that processes the generated Suricata eve-log in real time and, based on alerts, adds an ip-address to the MikroTik Address Lists for a specified time for subsequent blocking
suriGUI13about 4 years agoGUI for Suricata + Qubes OS

Backlinks from these awesome lists:

More related projects: