TedDriggs / cti
Cyber threat intelligence crates for Rust
☆15Updated last year
Alternatives and similar repositories for cti:
Users that are interested in cti are comparing it to the libraries listed below
- A cross platform forensic parser written in Rust!☆80Updated last week
- Framework definitions that allow to build a custom SIEM.☆25Updated 6 months ago
- A document tagging library☆30Updated 3 weeks ago
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆36Updated 2 years ago
- MalwareDB: bookkeeping for malware, goodware, and unknown files with relationship discovery☆44Updated this week
- Rust bindings for VirusTotal/Yara☆75Updated last month
- A parser for the MFT (Master File Table) format☆137Updated last year
- Alternative YARA scanning engine☆70Updated 2 years ago
- LOKI2 - Simple IOC and YARA Scanner☆89Updated 8 months ago
- File Capability Extractor☆13Updated last month
- PAL (Pcap Analysis Library)☆98Updated 4 months ago
- Python bindings for https://github.com/omerbenamram/evtx/☆50Updated last month
- A Rust library for managing eBPF programs.☆120Updated last year
- An open source platform to support analysts to organise their case and tasks☆71Updated this week
- This repository has been archived in favor of https://github.com/idaholab/Malcolm-Test-Artifacts☆33Updated 4 months ago
- Fast, inline geolocation decoration of IPv4 and IPv6 addresses written in Rust☆26Updated last year
- siquery, a Rust osquery implementation to query system information☆59Updated 2 years ago
- 🕵️♀️ Find, locate, and query files for ops and security experts ⚡️⚡️⚡️☆33Updated 2 years ago
- Safe and performant YARA rules evaluator in Rust☆46Updated last week
- A network packet synthesis language☆12Updated 3 months ago
- Convert Sigma Rules to different formats☆11Updated 8 months ago
- Rust implementation of the DCSO Bloom filter☆27Updated 3 weeks ago
- A Windows registry file parser written in Rust☆37Updated last year
- Extract machine readable cyber threat intelligence from unstructured data (inc. PDFs, Word docs, and HTML pages)☆14Updated this week
- This repository includes a mapping table and a reference process that allows converting between STIX 2.1 Course of Action objects that ma…☆16Updated 2 years ago
- An implementation of a Windows Event Collector server running on GNU/Linux.☆70Updated last week
- ☆11Updated 11 months ago
- Security Aware Wire Protocol parsing library☆38Updated 6 months ago
- provides a Suricata Eve output for Kafka with Suricate Eve plugin☆14Updated 3 years ago
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆70Updated last week