Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities
☆281Sep 15, 2026Updated this week
Alternatives and similar repositories for owLSM
Users that are interested in owLSM are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An idiomatic Rust mutex type for Windows kernel driver development.☆14Jan 24, 2026Updated 7 months ago
- Sandbox samples and monitor them with kunai☆29Jul 21, 2026Updated last month
- XDP Based Lightweight and Fast Firewall☆71Feb 23, 2026Updated 6 months ago
- ClickDetect is a vendor-agnostic alerting framework for threshold-based detection. It works with ClickHouse, OpenSearch/Elasticsearch, Vi…☆52Updated this week
- Run TTPs, with AI!☆142Feb 23, 2026Updated 6 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Jun 18, 2026Updated 3 months ago
- A Kubernetes Forensic Collection Framework for Azure Kubernetes Service☆44Feb 9, 2026Updated 7 months ago
- Hunt Smarter, Hunt Harder☆199Mar 14, 2026Updated 6 months ago
- ☆13Sep 22, 2022Updated 3 years ago
- Yara Based Detection Engine for web browsers☆50Sep 5, 2021Updated 5 years ago
- eBPF Security Monitoring and Sandboxing Agent Based on Aya☆65Updated this week
- LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footpr…☆20May 25, 2026Updated 3 months ago
- .NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on dis…☆41Jul 13, 2026Updated 2 months ago
- Deterministic Linux runtime enforcement with eBPF LSM: block file/network operations before syscalls complete.☆34Sep 8, 2026Updated last week
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Vulnerable EDR☆27Nov 15, 2024Updated last year
- Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !☆44Mar 24, 2026Updated 5 months ago
- ☆34Aug 8, 2023Updated 3 years ago
- surface-watch monitors the authorized external attack surface of an organization over time☆55May 11, 2026Updated 4 months ago
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆566Mar 24, 2026Updated 5 months ago
- Work In Progress☆10Jul 10, 2024Updated 2 years ago
- A Linux kernel integrity scanner☆18May 2, 2026Updated 4 months ago
- Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task…☆59Updated this week
- The MAGIC tool is a wrapper around the Microsoft Graph Python SDK, designed to download incident response-relevant data from M365 environ…☆35Apr 13, 2026Updated 5 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation an…☆29Sep 9, 2026Updated last week
- Self-hosted AI-assisted CTI-to-detection workbench for ATT&CK mapping, IOC/CVE intelligence, Threat Radar, malware triage, Attack Simulat…☆29Updated this week
- Extensible MacOS system telemetry generator.☆70Updated this week
- Yet, Another Packer/Loader☆25Feb 26, 2023Updated 3 years ago
- Maintained by the ANY.RUN team, this repository provides YARA rules to help detect and classify various malware families and other malici…☆31Nov 1, 2025Updated 10 months ago
- Kunai Sandbox UI☆18Mar 2, 2026Updated 6 months ago
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆34Feb 10, 2026Updated 7 months ago
- Offset Independent Credential Extraction Tool☆67Sep 2, 2025Updated last year
- Go module for running eBPF programs without root privileges or kernel eBPF support, powered by bpftime.☆15Feb 9, 2026Updated 7 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 4 months ago
- Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug…☆185Sep 10, 2026Updated last week
- A python script developed to process Windows memory images based on triage type.☆267Nov 25, 2023Updated 2 years ago
- Workshop: Forensic Analysis of eBPF based Linux Rootkits☆15Jul 9, 2026Updated 2 months ago
- BPFView: Process and Network Activity Correlation☆34May 17, 2025Updated last year
- A repository of Sysmon For Linux configuration modules☆17Oct 14, 2021Updated 4 years ago
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆193May 23, 2026Updated 3 months ago