Velocidex / vfilter
A library implementing a generic SQL like query language.
☆20Updated 2 weeks ago
Alternatives and similar repositories for vfilter:
Users that are interested in vfilter are comparing it to the libraries listed below
- Golang parser for OLE files☆31Updated 8 months ago
- An NTFS file parser in Go☆67Updated last week
- Go library MalShare API☆12Updated 5 years ago
- suricata eve.json parser in Go☆14Updated 5 years ago
- Golang port of pefile☆23Updated 7 years ago
- Collect autorun records from running system☆60Updated 3 years ago
- Golang port of PEFile☆29Updated 4 years ago
- gyp: A pure Go YARA parser☆106Updated 11 months ago
- A Golang API for TheHive☆13Updated 4 years ago
- Graphoscope is a solution to access multiple independent data sources from a common UI and show data relations as a graph☆37Updated 2 months ago
- A golang implementation of a prefetch parser.☆19Updated 5 months ago
- A Portable Executable parser for Golang☆47Updated last month
- A pure Go library for working with Structured Threat Information Expression (STIX™) version 2.x data☆23Updated 4 months ago
- Libgore☆13Updated last year
- NFDump File Reader☆11Updated 3 months ago
- A Go implementation and parser for Sigma rules.☆86Updated 5 months ago
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 3 years ago
- NTFS Master File Table (MFT) parser for Go.☆43Updated 6 months ago
- Go library for subscribing to Windows Event Log☆29Updated 5 years ago
- 📚 A collection of tools and libraries to parse filesystems, archives and other data types☆20Updated 4 months ago
- A golang DNS monitor inspired by https://github.com/gamelinux/passivedns☆29Updated this week
- File Capability Extractor☆13Updated 3 months ago
- Detect compiler names and versions from ELF files☆25Updated 5 months ago
- Yara powered NIDS with high speed packet capture powered by PF_RING☆68Updated 9 months ago
- Build a local copy of MITRE ATT&CK and CAPEC. Server mode for easy querying.☆32Updated this week
- A fault-tolerant events/alerts correlation engine☆25Updated 5 years ago
- GoSDDL converter☆11Updated 5 years ago
- Golang Parser for Microsoft Event Logs☆101Updated last month
- A web frontend to libpcap spool directories as produced by tcpdump or daemonlogger.☆26Updated 8 months ago
- dump network packet and log to database☆9Updated 2 years ago