TedDriggs / ctiLinks
Cyber threat intelligence crates for Rust
☆16Updated last year
Alternatives and similar repositories for cti
Users that are interested in cti are comparing it to the libraries listed below
Sorting:
- Framework definitions that allow to build a custom SIEM.☆28Updated last year
- MalwareDB: bookkeeping for malware, goodware, and unknown files with relationship discovery☆54Updated last week
- Rust implementation of the DCSO Bloom filter☆29Updated 5 months ago
- A cross platform forensic parser written in Rust!☆98Updated 3 weeks ago
- A document tagging library☆32Updated 8 months ago
- Rust bindings for VirusTotal/Yara☆80Updated last month
- A parser for the MFT (Master File Table) format☆150Updated 2 months ago
- A Rust library for parsing and evaluating Sigma rules☆19Updated 3 weeks ago
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆36Updated 3 years ago
- An implementation of a Windows Event Collector server running on GNU/Linux.☆86Updated 2 months ago
- SysFlow collection probe☆16Updated last month
- Python bindings for https://github.com/omerbenamram/evtx/☆53Updated 10 months ago
- LOKI2 - Simple IOC and YARA Scanner☆108Updated 5 months ago
- Security ML models encoded as Yara rules☆214Updated 2 years ago
- provides a Suricata Eve output for Kafka with Suricate Eve plugin☆15Updated 4 years ago
- Alternative YARA scanning engine☆73Updated 3 years ago
- File Capability Extractor☆14Updated 5 months ago
- Augmentation to Machine Readable CTI☆37Updated 3 months ago
- Golang library that implements a sigma log rule parser and match engine.☆103Updated last year
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆114Updated 7 months ago
- Trigram database written in C++, suited for malware indexing☆128Updated last year
- Basically a KrabsETW rip-off written in Rust☆79Updated 2 months ago
- Firepit - STIX Columnar Storage☆17Updated last year
- MuonFP is an enterprise ready, TCP passive fingerprinter written in Rust that has no external dependencies such as WireShark or other ope…☆29Updated last week
- PAL (Pcap Analysis Library)☆104Updated 4 months ago
- OASIS TC Open Repository: Non-normative schemas and examples for STIX 2☆130Updated last month
- MISP-STIX-Converter - Python library to handle the conversion between MISP and STIX formats☆56Updated this week
- Signature engine for all your logs☆173Updated 2 years ago
- An open source platform to support analysts to organise their case and tasks☆114Updated this week
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆167Updated 2 weeks ago