TedDriggs / cti
Cyber threat intelligence crates for Rust
☆13Updated last year
Alternatives and similar repositories for cti:
Users that are interested in cti are comparing it to the libraries listed below
- A document tagging library☆29Updated last week
- Framework definitions that allow to build a custom SIEM.☆25Updated 6 months ago
- Rust bindings for VirusTotal/Yara☆75Updated 3 weeks ago
- MalwareDB: bookkeeping for malware, goodware, and unknown files with relationship discovery☆41Updated this week
- Safe and performant YARA rules evaluator in Rust☆46Updated this week
- A cross platform forensic parser written in Rust!☆80Updated this week
- Fast, inline geolocation decoration of IPv4 and IPv6 addresses written in Rust☆26Updated last year
- File Capability Extractor☆13Updated last week
- PAL (Pcap Analysis Library)☆98Updated 4 months ago
- This repository has been archived in favor of https://github.com/idaholab/Malcolm-Test-Artifacts☆33Updated 3 months ago
- Security Aware Wire Protocol parsing library☆38Updated 5 months ago
- Convert Sigma Rules to different formats☆11Updated 7 months ago
- Pure Rust fuzzy hash implementation☆22Updated 2 years ago
- LOKI2 - Simple IOC and YARA Scanner☆87Updated 8 months ago
- Python bindings for https://github.com/omerbenamram/evtx/☆50Updated last month
- provides a Suricata Eve output for Kafka with Suricate Eve plugin☆14Updated 3 years ago
- Alternative YARA scanning engine☆68Updated 2 years ago
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆36Updated 2 years ago
- siquery, a Rust osquery implementation to query system information☆58Updated 2 years ago
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆69Updated 2 months ago
- Scanner for certain IoCs☆11Updated 2 months ago
- Allows Rust code to log events to ETW☆102Updated 5 months ago
- Sighting DB is designed to scale writing and reading a count of attributes, tracking when if was first and last seen☆16Updated 11 months ago
- YARA rule metadata specification and validation utility / Spécification et validation pour les règles YARA☆101Updated this week
- Private Search Set (PSS) is an extension to standard Bloom filter or a standalone hash file to describe and share private set.☆16Updated 2 months ago
- Threat Detection Rules (Snort/Sigma/Yara)☆13Updated last year
- SightingDB is a database for Sightings☆22Updated last year
- Automated Yara Rule generation using Biclustering☆66Updated 3 years ago
- SysFlow collection probe☆16Updated 2 months ago
- YARI is an interactive debugger for YARA Language.☆88Updated 2 months ago