AbGuthrie / goquery
Provide a shell like interface by utilizing osquery's distributed API
☆81Updated 4 years ago
Alternatives and similar repositories for goquery:
Users that are interested in goquery are comparing it to the libraries listed below
- Competition Infrastructure Management☆87Updated 3 years ago
- How to Zeek Sysmon Logs!☆101Updated 3 years ago
- Collect autorun records from running system☆61Updated 3 years ago
- Golang command line tool for the macOS Endpoint Security Framework☆29Updated 5 years ago
- Bro/Zeek integration with osquery☆94Updated 4 years ago
- Osquery Mangement Server☆114Updated 4 years ago
- A CLI tool for querying passive DNS services☆41Updated last year
- Things to know when DFIR occurs near a vault deployment.☆43Updated 6 years ago
- Going Florida on container keyring masks. A tool to demonstrate the ineffectivity containers have on isolating Linux Kernel keyrings.☆43Updated last year
- A YARA Rule Performance Measurement Tool☆59Updated last year
- Import specific data sources into the Sigma generic and open signature format.☆78Updated 2 years ago
- Osquery Resources☆60Updated 5 years ago
- Recon Hunt Queries☆76Updated 3 years ago
- Yara-Endpoint is a tool useful for incident response as well as anti-malware enpoint base on Yara signatures.☆108Updated 7 years ago
- Indicator Extractor☆139Updated 6 years ago
- rules to identify files containing juicy information like usernames, passwords etc☆128Updated 7 years ago
- Sandbox feature upgrade with the help of wrapped samples☆76Updated 6 years ago
- ☆33Updated 3 years ago
- Security conferences talks☆25Updated 4 years ago
- ☆53Updated 6 years ago
- threat-intelligence.eu website and repository of information about open standards, documents, methodologies and processes in threat intel…☆48Updated 2 years ago
- A MITRE Caldera plugin written in Python 3 used to convert Red Canary Atomic Red Team Tests to MITRE Caldera Stockpile YAML ability files…☆71Updated 3 years ago
- Extract indicators of compromise from text, including "escaped" ones.☆159Updated 5 years ago
- pollen - A command-line tool for interacting with TheHive☆35Updated 5 years ago
- Yara Dockerfile☆50Updated 2 years ago
- Simple Docker-based quickstart for osquery, Fleet, and ELK stack☆63Updated last year
- Simple Docker Honeypot server emulating small snippets of the Docker HTTP API☆30Updated 4 years ago
- Website crawler with YARA detection☆88Updated last year
- Automated testing, generation & manipulation of #osquery packs☆72Updated 6 months ago
- Tools for parsing rulesets using the exact grammar as YARA. Written in Go.☆83Updated 2 years ago