🐍 High-performance, multi-threaded YARA & IOC scanner
☆342Jul 20, 2026Updated this week
Alternatives and similar repositories for Loki-RS
Users that are interested in Loki-RS are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A Compiler from Sigma rules to VQL☆19May 18, 2026Updated 2 months ago
- A YARA rule generator☆80Feb 8, 2026Updated 5 months ago
- Automated YARA Rule Standardization and Quality Assurance Tool☆329Updated this week
- Community-driven PowerShell detection indicators☆39Jan 27, 2026Updated 5 months ago
- Loki - Simple IOC and YARA Scanner☆3,770Jan 12, 2026Updated 6 months ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Generate malware traces for detection tests☆16Updated this week
- Convert Sigma rules to SIEM queries, directly in your browser.☆121Jun 20, 2026Updated last month
- Bring Your Own Mitre Att&ck © Matrix !☆13Oct 19, 2023Updated 2 years ago
- YARA signature and IOC database for my scanners and tools☆2,998Jun 17, 2026Updated last month
- A small experiment on assigning a processes threads a specific CPU and then blocking it with a high priority thread☆33Sep 24, 2025Updated 9 months ago
- LibIPC is a simple Crystal Palace shared library for inter-process communication, based on Named Pipes.☆29Nov 4, 2025Updated 8 months ago
- GoResolver is a Go analysis tool using both Go symbol extraction and Control Flow Graph (CFG) similarity to identify and resolve the func…☆114Jan 26, 2026Updated 5 months ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆93Mar 11, 2026Updated 4 months ago
- surface-watch monitors the authorized external attack surface of an organization over time☆56May 11, 2026Updated 2 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Hayabusa (隼) is a sigma-based threat hunting and fast forensics timeline generator for Windows event logs.☆3,261Updated this week
- A collection of my yara rules☆34Jul 11, 2023Updated 3 years ago
- Rapidly Search and Hunt through Windows Forensic Artefacts☆3,604Updated this week
- Parses cached certificate templates from a Windows Registry file and displays them in the same style as Certipy does☆96Jul 3, 2025Updated last year
- Documentation and scripts to properly enable Windows event logs.☆710Oct 3, 2025Updated 9 months ago
- Sh3ller is a lightweight C2 framework in its simplest form.☆33Sep 5, 2025Updated 10 months ago
- Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSO…☆433Updated this week
- Windows protocol library, including SMB and RPC implementations, among others.☆805Jul 14, 2026Updated last week
- The MAGIC tool is a wrapper around the Microsoft Graph Python SDK, designed to download incident response-relevant data from M365 environ…☆35Apr 13, 2026Updated 3 months ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- Sanctum is an experimental proof-of-concept EDR, designed to detect modern malware techniques, above and beyond the capabilities of antiv…☆566Mar 24, 2026Updated 3 months ago
- DFIR Timeline Analysis for macOS — SQLite-backed viewer for CSV, TSV, XLSX, EVTX, Plaso, $MFT, and $J files with AI Artifacts, AI Secret …☆296Jun 6, 2026Updated last month
- A cmake template for crystal palace☆43Dec 20, 2025Updated 7 months ago
- A guide on how to write fast and memory friendly YARA rules☆174Feb 11, 2025Updated last year
- This project aims to compare and evaluate the telemetry of various EDR products.☆1,975Jul 7, 2026Updated last week
- SilentButDeadly is a network communication blocker specifically designed to neutralize EDR/AV software by preventing their cloud connecti…☆454Nov 3, 2025Updated 8 months ago
- A Payload Analysis Framework☆123Oct 9, 2025Updated 9 months ago
- Language extension for Crystal Palace Specification files☆15Jun 6, 2026Updated last month
- early cascade injection PoC based on Outflanks blog post, in rust☆64Nov 8, 2024Updated last year
- Managed hosting for WordPress and PHP on Cloudways • AdManaged hosting for WordPress, Magento, Laravel, or PHP apps, on multiple cloud providers. Deploy in minutes on Cloudways by DigitalOcean.
- An alternative to the builtin clipboard feature in Cobalt Strike that adds the capability to enable/disable and dump the clipboard histor…☆114Apr 16, 2026Updated 3 months ago
- .NET process monitor that hooks CLR at the native layer, dumps reflective assemblies from memory, and checks AMSI/ETW integrity vs on dis…☆40Jul 13, 2026Updated last week
- A POC for developing BOFs for Sliver, Havoc, Cobalt Strike or most COFFLoaders in Rust.☆76Aug 24, 2025Updated 10 months ago
- C2-agnostic BOF collection, categorized by attack chain phase. Designed to be small and modular, allowing for quick execution and automat…☆311Jul 5, 2026Updated 2 weeks ago
- BYOVD hunter to help prioritize windows drivers worth manual analysis☆131Aug 19, 2025Updated 11 months ago
- Proof-of-concept code for understanding the allow-jit entitlement on macOS☆37Feb 19, 2026Updated 5 months ago
- Async BOF that monitors USB device connect/disconnect events, reports device information and performs actions on connected USB storage vo…☆56Jun 17, 2026Updated last month