AbGuthrie / goqueryLinks
Provide a shell like interface by utilizing osquery's distributed API
☆81Updated 4 years ago
Alternatives and similar repositories for goquery
Users that are interested in goquery are comparing it to the libraries listed below
Sorting:
- Bro/Zeek integration with osquery☆94Updated 4 years ago
- Osquery Resources☆60Updated 5 years ago
- Things to know when DFIR occurs near a vault deployment.☆43Updated 7 years ago
- Recon Hunt Queries☆77Updated 4 years ago
- Competition Infrastructure Management☆87Updated 3 years ago
- Yara-Endpoint is a tool useful for incident response as well as anti-malware enpoint base on Yara signatures.☆109Updated 7 years ago
- Automatically create YARA rules from malicious documents.☆211Updated 3 years ago
- Going Florida on container keyring masks. A tool to demonstrate the ineffectivity containers have on isolating Linux Kernel keyrings.☆43Updated last year
- Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container☆106Updated 6 years ago
- ☆53Updated 6 years ago
- ☆34Updated 3 years ago
- Website crawler with YARA detection☆88Updated last year
- A Go implementation of JARM☆118Updated 3 years ago
- Centralize Management of Intrusion Detection System like Suricata Bro Ossec ...☆72Updated 6 years ago
- simple YARA-based IOC scanner☆169Updated 4 months ago
- A Spicy protocol analyzer for WireGuard☆29Updated 4 years ago
- Sigma Engine implementation in TypeScript☆28Updated 2 years ago
- Use Markov Chains to obfuscate data as other data☆54Updated 8 years ago
- Collect autorun records from running system☆60Updated 3 years ago
- Security conferences talks☆25Updated 4 years ago
- A CLI tool for querying passive DNS services☆41Updated last year
- defendA Data Lake. A firehose pipeline to athena providing enrichment and normalization for security events☆16Updated 2 years ago
- pollen - A command-line tool for interacting with TheHive☆35Updated 6 years ago
- AWS EKS Cluster Forensics☆23Updated 3 years ago
- A MITRE Caldera plugin written in Python 3 used to convert Red Canary Atomic Red Team Tests to MITRE Caldera Stockpile YAML ability files…☆71Updated 3 years ago
- Paper and Links to Crimeware in the Modern Era☆31Updated 5 years ago
- Simple Docker-based quickstart for osquery, Fleet, and ELK stack☆63Updated last year
- Interactive Threat Intelligence Bot that leverages serverless framework, AWS/GCP, and Slack☆27Updated 5 years ago
- A RESTful API frontend for Stenographer☆54Updated 2 years ago
- How to Zeek Sysmon Logs!☆102Updated 3 years ago