This is my variant of nfOTX plugin by @PacketInspector. I rewrote the original nfotx.pl to nfotx.py and added check for my own ip reputation data file.
This is the plugin for reading MS Endpoint Protection events from System Center Configuration Manager database. Also contains configuration files for creating view in SCCM DB and for Freedts on OSSIM server (need for cyrillic chars in SCCM DB)
There are two plugins for parsing FWS and WEB w3c logs from MS TMG 2010 on AlienVaul OSSIM and modified ParserUtil.py
tmg-web plugin and PerserUtil.py modified for add event sid 2 - Exchange ActyveSync Sync command
This is the instruction how to make OSSIM properly display Russian text on the screen and when you export to csv. Usefull for ossec-agent on Russian Windows and for database type connectors for MSSQL databases.
And check_encoding.py script. See instruction.txt for details
This is usefull python script for make csv file with the report of the integrity change, application install/uninstall regestered by ossec agent. This is for Russians :) cp1251 encoding used for working with Russian Windows and Excel
This is usefull Python script to generate csv file with report of user account and group membership change based on ossec agent data stored in AlienVault OSSIM. This is for Russians :) cp1251 used for Russian Windows and Excel
This is the Python script for reporting Cisco AnyConnect (ip to user assign) events from OSSIM cisco-asa plugin data as csv file.
2015-07-09. Added ActiveSync events from my activesync-monitor plugin and GeoIP data (geolite2)
Be careful!!! you MUST previosly install geoip2 python module becouse it not installed by default
wget https://bootstrap.pypa.io/get-pip.py --no-check-certificate python get-pip.py pip install geoip2
This is the simple Python script for generate the csv file from OSSIM database with "possible data leak" events collected by my own tmg-web plugin. "possible data leak" events have generated by plugin when large amount of data transfered to external host.
This is the Python script for reporting NfOTX Match events wich collected in OSSIM database by my modification of NfOTX plugin (initialy created by @PacketInspector). The script generate csv file with list of events and list of corresponded Netwlow data, so you can see what happend.
This is the Python script wich create a csv report file from the OSSIM with suricata events and corresponding netflow data for the giving asset group. Used cp1251 encoding for Russian Windows and Excel