Skip to content

Instantly share code, notes, and snippets.

ESGuardian

Block or report user

Report or block ESGuardian

Hide content and notifications from this user.

Learn more about blocking users

Contact Support about this user’s behavior.

Learn more about reporting abuse

Report abuse
View GitHub Profile
View !ossim_cyrillic_chars.md

This is the instruction how to make OSSIM properly display Russian text on the screen and when you export to csv. Usefull for ossec-agent on Russian Windows and for database type connectors for MSSQL databases.

And check_encoding.py script. See instruction.txt for details

@ESGuardian
ESGuardian / !ossim_tmg_plugin.md
Last active Aug 29, 2015
OSSIM plugin for MS TMG 2010 (Using SNARE Epilog for send FWS and WEB w3c formated logs to syslog)
View !ossim_tmg_plugin.md

There are two plugins for parsing FWS and WEB w3c logs from MS TMG 2010 on AlienVaul OSSIM and modified ParserUtil.py

tmg-web plugin and PerserUtil.py modified for add event sid 2 - Exchange ActyveSync Sync command

@ESGuardian
ESGuardian / !ossim_plugin_msfep.md
Last active Aug 29, 2015
OSSIM plugin for MS FEP (note about freetds.conf if you are not native american)
View !ossim_plugin_msfep.md

This is the plugin for reading MS Endpoint Protection events from System Center Configuration Manager database. Also contains configuration files for creating view in SCCM DB and for Freedts on OSSIM server (need for cyrillic chars in SCCM DB)

@ESGuardian
ESGuardian / !ossim_plugin_myILO.md
Last active Jul 3, 2019
OSSIM plugin for HP iLO
View !ossim_plugin_myILO.md

This is the plugin for parsing HP iLO v. 4 login/logout events on AlienVault OSSIM

@ESGuardian
ESGuardian / !ossim_plugin_nfotx.md
Last active Aug 29, 2015
Python variant of nfotx.pl created by AlienVault community user @packetinspector
View !ossim_plugin_nfotx.md

This is my variant of nfOTX plugin by @PacketInspector. I rewrote the original nfotx.pl to nfotx.py and added check for my own ip reputation data file.

You can’t perform that action at this time.