py-idstools VS wazuh-ruleset

Compare py-idstools vs wazuh-ruleset and see what are their differences.

InfluxDB - Power Real-Time Data Analytics at Scale
Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.
www.influxdata.com
featured
SaaSHub - Software Alternatives and Reviews
SaaSHub helps you find the best software and product alternatives
www.saashub.com
featured
py-idstools wazuh-ruleset
1 1
269 319
- -
5.6 4.7
6 months ago over 2 years ago
Python Python
GNU General Public License v3.0 or later -
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.

py-idstools

Posts with mentions or reviews of py-idstools. We have used some of these posts to build our list of alternatives and similar projects.
  • Regex Challenge - Field Extraction
    1 project | /r/Splunk | 12 Jun 2023
    I like this a lot. We have a in-house Snort 2 forwarder that does a similar thing with https://github.com/jasonish/py-idstools and forwards the result directly using HEC. We could use the same code base for dnstap if we wanted.

wazuh-ruleset

Posts with mentions or reviews of wazuh-ruleset. We have used some of these posts to build our list of alternatives and similar projects.
  • Windows events alerts with Wazuh
    1 project | /r/Wazuh | 19 Mar 2021
    In this repository https://github.com/wazuh/wazuh-ruleset you can find the decoders and rules that wazuh-manager has by default (all these files are being migrated to the repository wazuh/wazuh https://github.com/wazuh/wazuh).

What are some alternatives?

When comparing py-idstools and wazuh-ruleset you can also consider the following projects:

snort-rules - An UNOFFICIAL Git Repository of Snort Rules(IDS rules) Releases. [UnavailableForLegalReasons - Repository access blocked]

sigma - Main Sigma Rule Repository

Malcolm - Malcolm is a powerful, easily deployable network traffic analysis tool suite for full packet capture artifacts (PCAP files), Zeek logs and Suricata alerts.

Fail2Ban - Daemon to ban hosts that cause multiple authentication errors

openscap - NIST Certified SCAP 1.2 toolkit

openwisp-monitoring - Network monitoring system written in Python and Django, designed to be extensible, programmable, scalable and easy to use by end users: once the system is configured, monitoring checks, alerts and metric collection happens automatically.

loglizer - A machine learning toolkit for log-based anomaly detection [ISSRE'16]

Check-WP-CVE-2020-35489 - The (WordPress) website test script can be exploited for Unlimited File Upload via CVE-2020-35489

sysmon - Sysmon and wazuh integration with Sigma sysmon rules [updated]

OSSEC - OSSEC is an Open Source Host-based Intrusion Detection System that performs log analysis, file integrity checking, policy monitoring, rootkit detection, real-time alerting and active response.

RedELK - Red Team's SIEM - tool for Red Teams used for tracking and alarming about Blue Team activities as well as better usability in long term operations.

flake8-bandit - Automated security testing using bandit and flake8.