0x00000013 / huakiwiLinks
eBPF-based EDR for Linux
☆18Updated last year
Alternatives and similar repositories for huakiwi
Users that are interested in huakiwi are comparing it to the libraries listed below
Sorting:
- Yara powered NIDS with high speed packet capture powered by PF_RING☆69Updated last year
- A collection of projects demonstrating various commandline cloaking techniques on Linux☆59Updated 3 years ago
- Golang Port Knocking for Linux + Windows☆18Updated 3 years ago
- Collect autorun records from running system☆60Updated 3 years ago
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 4 years ago
- ☆89Updated last year
- YARI is an interactive debugger for YARA Language.☆89Updated last month
- Red Canary's eBPF Sensor☆110Updated 4 months ago
- Look into EDR events from network☆24Updated 5 months ago
- Provides a multi-platform Graphical User Interface for hashlookup☆12Updated last year
- JA4TScan is an active TCP server fingerprinting tool.☆91Updated last year
- 🚧 Currently transfering TLP:CLEAR rules from TLP:AMBER repository...☆21Updated last year
- WhiteBeam: Transparent endpoint security☆100Updated 2 years ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆137Updated 2 years ago
- Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives …☆164Updated last year
- Suricata rule and intel index☆32Updated last month
- Tiny embeddable dns server☆52Updated last week
- A Portable Executable parser for Golang☆47Updated 9 months ago
- Sandfly Linux Stealth Rootkit Decloaking Utility☆104Updated 2 years ago
- Hybrid memory/disk map☆59Updated last week
- Recog-Go: Pattern Recognition using Rapid7 Recog☆118Updated 2 years ago
- Accurate, modular, scalable PCAP manipulation tool written in Go.☆94Updated last year
- Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.☆26Updated 2 weeks ago
- ☆41Updated 3 years ago
- A Go implementation of JARM☆119Updated 3 years ago
- Linux rust keylogger☆17Updated last year
- Linux based vulnerabilities (CVE) exploit detection through runtime security using Falco/Osquery/Yara/Sigma☆21Updated last year
- This tool have the power to hide any PID/directory in the Linux kernel☆29Updated last year
- A set of YARA rules for the AIL framework to detect leak or information disclosure☆38Updated 8 months ago
- Advanced threat detection solution for Linux.☆35Updated 4 years ago