HoneProject / Linux-Sensor
Correlate packets to the responsible processes in Linux systems. Diagnose connections by adding process information.
☆103Updated 9 years ago
Alternatives and similar repositories for Linux-Sensor:
Users that are interested in Linux-Sensor are comparing it to the libraries listed below
- ssltrace hooks an application's SSL libraries to record keying data of all SSL connections☆94Updated 9 years ago
- iknowthis Linux SystemCall Fuzzer☆20Updated 5 years ago
- ☆24Updated 9 years ago
- Convert libvirt-QEMU-save (LQS) files to raw memory files☆37Updated last year
- BONOMEN - Hunt for Malware Critical Process Impersonation☆47Updated 4 years ago
- Using nDPI/openDPI to detect flow protocols from a PCAP file or live NIC. This program was modified from example in nDPI and I added a pe…☆23Updated 8 years ago
- PoC to append and extract data at the end of an ELF file☆20Updated 7 years ago
- Extract TLS certificates from pcap files or network interfaces, fingerprint TLS client/server interactions with ja3/ja3s☆38Updated 5 years ago
- A simple, but damn fast sinkhole☆63Updated last month
- intel amt honeypot☆18Updated 7 years ago
- An Interactive Pcap Editor (based on Scapy)☆23Updated 4 years ago
- Be able to execute memory snapshots so they can start running where they left off.☆35Updated 9 years ago
- Membrane: A Posteriori Detection of Malicious Code Loading by Memory Paging Analysis☆42Updated 8 years ago
- A tool like /bin/ps but uses /proc/kcore for walking the tasklist; this finds hidden processes☆57Updated 9 years ago
- tracy - a system call tracer and injector. Find us in #tracy on irc.freenode.net☆72Updated 5 years ago
- DNS packet generator☆42Updated 5 months ago
- Script that dumps running process memory from Linux systems using /proc.☆79Updated 11 years ago
- runtime code injector for Linux☆27Updated 13 years ago
- ☆35Updated 12 years ago
- A tool to generate log messages related to interfaces, neighbor cache (ARP,NDP), IP address, routing, FIB rules, traffic control.☆32Updated 3 months ago
- Stealth's 64bit injectso port☆74Updated 14 years ago
- Does your library check TLS certificates properly?☆78Updated last year
- Passive DHCP fingerprinting implementation☆50Updated 8 years ago
- Linux kernel - See Landlock issues☆35Updated last month
- viewssld is a free, open source, non-terminating SSLv2/SSLv3/TLS traffic decryption daemon for Snort, and other Network Intrusion Detecti…☆74Updated 7 years ago
- SIGSTOPing ELF binaries since 0x7E1☆51Updated 5 months ago
- LD_PRELOAD library for intercepting the plain text of SSL connections made with openssl☆24Updated 10 years ago
- Verification Validation and Visualization of Security Policy Abstractions☆43Updated last year
- r2yara - Module for Yara using radare2 information☆34Updated last year
- Ccollection of Linux loadable kernel modules aimed to logs any user action☆25Updated 5 years ago