Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities
☆281Oct 5, 2026Updated this week
Alternatives and similar repositories for owLSM
Users that are interested in owLSM are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An idiomatic Rust mutex type for Windows kernel driver development.☆14Jan 24, 2026Updated 8 months ago
- Sandbox samples and monitor them with kunai☆31Jul 21, 2026Updated 2 months ago
- XDP Based Lightweight and Fast Firewall☆71Feb 23, 2026Updated 7 months ago
- Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security…☆38Mar 16, 2026Updated 6 months ago
- ClickDetect is a vendor-agnostic alerting framework for threshold-based detection. It works with ClickHouse, OpenSearch/Elasticsearch, Vi…☆51Sep 14, 2026Updated 3 weeks ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Run TTPs, with AI!☆142Feb 23, 2026Updated 7 months ago
- A Kubernetes Forensic Collection Framework for Azure Kubernetes Service☆44Feb 9, 2026Updated 8 months ago
- Hunt Smarter, Hunt Harder☆199Mar 14, 2026Updated 6 months ago
- ☆13Sep 22, 2022Updated 4 years ago
- MAD-CAT (Meow Attack Data Corruption Automation Tool) is a comprehensive security tool designed to simulate data corruption attacks again…☆38Sep 25, 2026Updated 2 weeks ago
- Yara Based Detection Engine for web browsers☆50Sep 5, 2021Updated 5 years ago
- eBPF Security Monitoring and Sandboxing Agent Based on Aya☆76Updated this week
- LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footpr…☆20May 25, 2026Updated 4 months ago
- .NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on dis…☆41Jul 13, 2026Updated 2 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Deterministic Linux runtime enforcement with eBPF LSM: block file/network operations before syscalls complete.☆37Updated this week
- Vulnerable EDR☆27Nov 15, 2024Updated last year
- ☆35Aug 8, 2023Updated 3 years ago
- A lightweight, multi-layer Linux sandbox combining namespaces, pivot_root, seccomp-bpf, capability dropping, and an evidence-based verdic …☆74Aug 26, 2026Updated last month
- surface-watch monitors the authorized external attack surface of an organization over time☆55May 11, 2026Updated 4 months ago
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆567Mar 24, 2026Updated 6 months ago
- Endpoint detection for Windows, Linux, and macOS. Sigma, YARA, and IOC rules on native telemetry. Written in Rust. No cloud account requi…☆502Updated this week
- Work In Progress☆10Jul 10, 2024Updated 2 years ago
- A Linux kernel integrity scanner☆18May 2, 2026Updated 5 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task…☆58Updated this week
- The MAGIC tool is a wrapper around the Microsoft Graph Python SDK, designed to download incident response-relevant data from M365 environ…☆35Apr 13, 2026Updated 5 months ago
- An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation an…☆29Sep 9, 2026Updated last month
- ☆17Jul 23, 2024Updated 2 years ago
- Self-hosted AI-assisted CTI-to-detection workbench for ATT&CK mapping, IOC/CVE intelligence, Threat Radar, malware triage, Attack Simulat…☆31Oct 1, 2026Updated last week
- Extensible MacOS system telemetry generator.☆72Sep 15, 2026Updated 3 weeks ago
- Yet, Another Packer/Loader☆25Feb 26, 2023Updated 3 years ago
- Maintained by the ANY.RUN team, this repository provides YARA rules to help detect and classify various malware families and other malici…☆32Nov 1, 2025Updated 11 months ago
- Kunai Sandbox UI☆18Mar 2, 2026Updated 7 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Offset Independent Credential Extraction Tool☆69Sep 2, 2025Updated last year
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆32Feb 10, 2026Updated 8 months ago
- A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.☆286Sep 23, 2025Updated last year
- Go module for running eBPF programs without root privileges or kernel eBPF support, powered by bpftime.☆15Feb 9, 2026Updated 8 months ago
- Experimental Linux strace LLM agent☆21Apr 23, 2026Updated 5 months ago
- COM Windows Persistence Technique☆89Apr 27, 2026Updated 5 months ago
- Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug…☆186Updated this week