Skip to content
@corelight

Corelight, Inc.

Corelight is the most powerful network visibility solution for information security professionals, founded by the creators of open-source Zeek.

Popular repositories Loading

  1. zeek-cheatsheets zeek-cheatsheets Public

    Zeek Log Cheatsheets

    284 45

  2. community-id-spec community-id-spec Public

    An open standard for hashing network flows into identifiers, a.k.a "Community IDs".

    Python 170 25

  3. threat-hunting-guide threat-hunting-guide Public

    46 11

  4. raspi-corelight raspi-corelight Public

    Corelight@Home script

    Shell 40 5

  5. zeek2es zeek2es Public

    A Python application to filter and transfer Zeek logs to Elastic/OpenSearch+Humio. This app can also output pure JSON logs to stdout for further processing!

    Python 35 7

  6. zeek-community-id zeek-community-id Public

    Zeek support for Community ID flow hashing.

    Zeek 34 18

Repositories

Showing 10 of 141 repositories
  • Chronicle Public

    Chronicle parser for CORELIGHT and related information.

    corelight/Chronicle’s past year of commit activity
    Python 3 4 0 1 Updated Nov 8, 2024
  • corelight/Zeek-Endpoint-Enrichment’s past year of commit activity
    Zeek 2 1 0 1 Updated Nov 7, 2024
  • Zeek-Endpoint-Enrichment-conn Public

    Enrich the conn.log with EDR data

    corelight/Zeek-Endpoint-Enrichment-conn’s past year of commit activity
    Zeek 1 0 0 0 Updated Nov 7, 2024
  • corelight/Zeek-Endpoint-Enrichment-all’s past year of commit activity
    Zeek 1 0 0 0 Updated Nov 7, 2024
  • icannTLD Public

    Zeek script using the official ICANN Top-Level Domain (TLD) list with the Input Framework to extract the relevant information from a DNS query and mark whether it's trusted or not. The source of the ICANN TLD's can be found here: https://publicsuffix.org/list/effective_tld_names.dat. The Trusted Domains list is a custom list, created by the user…

    corelight/icannTLD’s past year of commit activity
    Zeek 5 5 0 0 Updated Nov 7, 2024
  • terraform-gcp-enrichment Public

    Terraform for Corelight's GCP Cloud Enrichment.

    corelight/terraform-gcp-enrichment’s past year of commit activity
    HCL 0 MIT 0 0 0 Updated Nov 6, 2024
  • terraform-gcp-sensor Public

    Terraform for Corelight's GCP Cloud Sensor Deployment.

    corelight/terraform-gcp-sensor’s past year of commit activity
    HCL 1 MIT 0 0 0 Updated Nov 6, 2024
  • terraform-azure-enrichment Public

    Terraform for Corelight's Azure Cloud Enrichment.

    corelight/terraform-azure-enrichment’s past year of commit activity
    HCL 0 MIT 0 0 0 Updated Nov 6, 2024
  • terraform-azure-sensor Public

    Terraform for Corelight's Azure Cloud Sensor Deployment.

    corelight/terraform-azure-sensor’s past year of commit activity
    HCL 1 MIT 0 0 0 Updated Nov 6, 2024
  • terraform-aws-enrichment Public

    Terraform for Corelight's AWS Cloud Enrichment.

    corelight/terraform-aws-enrichment’s past year of commit activity
    HCL 1 MIT 0 0 0 Updated Nov 6, 2024