Skip to content

Toolkit to take an EclecticIQ JSON outgoing feed, extract the useful observables and transform those into IDS rulesets.

License

Notifications You must be signed in to change notification settings

KPN-CISO/EIQ-to-IDS

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

80 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

EIQ-to-IDS

Toolkit to take an EclecticIQ JSON outgoing feed, extract the useful observables and transform those into IDS rulesets.

Please note that we consider this to be proof-of-concept code for generating Snort/SourceFire rules. You should really not blindly run this on production environments without careful checking of the generated rulesets.

Check back regularly for updates, as development will continue.

About

Toolkit to take an EclecticIQ JSON outgoing feed, extract the useful observables and transform those into IDS rulesets.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages