Sigma Rules Engine inside the Linux Kernel using eBPF. Focusing on prevention capabilities
☆280Jul 30, 2026Updated last week
Alternatives and similar repositories for owLSM
Users that are interested in owLSM are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- An idiomatic Rust mutex type for Windows kernel driver development.☆15Jan 24, 2026Updated 6 months ago
- Anvil is a runtime-first attack surface assessment tool for Windows thick client applications, built for penetration testers and security…☆37Mar 16, 2026Updated 4 months ago
- XDP Based Lightweight and Fast Firewall☆70Feb 23, 2026Updated 5 months ago
- ClickDetect is a vendor-agnostic alerting framework for threshold-based detection. It works with ClickHouse, OpenSearch/Elasticsearch, Vi…☆51Updated this week
- Sandbox samples and monitor them with kunai☆29Jul 21, 2026Updated 2 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Run TTPs, with AI!☆140Feb 23, 2026Updated 5 months ago
- MAD-CAT (Meow Attack Data Corruption Automation Tool) is a comprehensive security tool designed to simulate data corruption attacks again…☆37Oct 11, 2025Updated 9 months ago
- Hunt Smarter, Hunt Harder☆199Mar 14, 2026Updated 4 months ago
- CyberChef - Detection Engineering, TI, DFIR, Malware Analysis Edition☆66Jun 18, 2026Updated last month
- A Kubernetes Forensic Collection Framework for Azure Kubernetes Service☆44Feb 9, 2026Updated 6 months ago
- Bypassing EDR's with stealthy c++ telegram Bot and Telegram itself as C2 interface !☆43Mar 24, 2026Updated 4 months ago
- ☆13Sep 22, 2022Updated 3 years ago
- eBPF Security Monitoring and Sandboxing Agent Based on Aya☆53Aug 3, 2026Updated last week
- Yara Based Detection Engine for web browsers☆50Sep 5, 2021Updated 4 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- surface-watch monitors the authorized external attack surface of an organization over time☆56May 11, 2026Updated 2 months ago
- An extensible, deterministic static‑analysis engine that extracts high‑signal IOCs from PE binaries and text, built for SOC automation an…☆28Jul 31, 2026Updated last week
- The MAGIC tool is a wrapper around the Microsoft Graph Python SDK, designed to download incident response-relevant data from M365 environ…☆35Apr 13, 2026Updated 3 months ago
- LID — Linux Integrity Drift: Bypassing AppArmor via eBPF pathname rewriting. Pre-LSM syscall argument manipulation with zero audit footpr…☆19May 25, 2026Updated 2 months ago
- Deterministic Linux runtime enforcement with eBPF LSM: block file/network operations before syscalls complete.☆18Updated this week
- A VS Code plugin to execute arbitrary JavaScript code at runtime over a local HTTP endpoint.☆33Feb 10, 2026Updated 6 months ago
- .NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on dis…☆41Jul 13, 2026Updated 3 weeks ago
- Extensible MacOS system telemetry generator.☆62Updated this week
- Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSO…☆448Updated this week
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- ☆34Aug 8, 2023Updated 3 years ago
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆568Mar 24, 2026Updated 4 months ago
- Offset Independent Credential Extraction Tool☆54Sep 2, 2025Updated 11 months ago
- Linux Persistence Detection, Hunting and Artifact Collection script☆25Jul 20, 2026Updated 3 weeks ago
- Work In Progress☆10Jul 10, 2024Updated 2 years ago
- Jailer is an eBPF-based process jailing system that provides mandatory access control (MAC) for Linux. It tracks processes using BPF task…☆58Aug 2, 2026Updated last week
- A Linux kernel integrity scanner☆17May 2, 2026Updated 3 months ago
- Microsoft Vulnerable Driver Block Lists in CSV and JSON for SIEM lookups☆55May 15, 2026Updated 2 months ago
- Self-hosted AI-assisted CTI-to-detection workbench for ATT&CK mapping, IOC/CVE intelligence, Threat Radar, malware triage, Attack Simulat…☆26Updated this week
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- A PoC Cobalt Strike UDRL written in Rust☆33Jun 20, 2026Updated last month
- A comprehensive ETW (Event Tracing for Windows) event generation tool designed for testing and research purposes.☆275Sep 23, 2025Updated 10 months ago
- Post-exploitation framework that abuses trusted sites like Telegram and Discord for C2.☆71Apr 24, 2026Updated 3 months ago
- Zero-dependency Linux memory forensics, leveraging kernel-embedded BTF and kallsyms for type-aware memory analysis without external debug…☆184Updated this week
- Yet, Another Packer/Loader☆25Feb 26, 2023Updated 3 years ago
- EDRStartupHinder: A red team tool to prevent Antivirus and EDR from running.☆195May 23, 2026Updated 2 months ago
- Maintained by the ANY.RUN team, this repository provides YARA rules to help detect and classify various malware families and other malici…☆31Nov 1, 2025Updated 9 months ago