bi-zone / etwLinks
Go library for ETW (Event Tracing for Windows) events processing
☆68Updated 3 years ago
Alternatives and similar repositories for etw
Users that are interested in etw are comparing it to the libraries listed below
Sorting:
- ☆41Updated 3 years ago
- Golang Parser for Microsoft Event Logs☆105Updated 3 months ago
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 4 years ago
- ☆166Updated 2 years ago
- Signature engine for all your logs☆171Updated last year
- A Go implementation of JARM☆119Updated 3 years ago
- Golang parser for OLE files☆32Updated 6 months ago
- A Go implementation and parser for Sigma rules.☆92Updated 4 months ago
- Yapscan is a YAra based Process SCANner, aimed at giving more control about what to scan and giving detailed reports on matches.☆62Updated 2 years ago
- Cobalt Strike Beacon configuration extractor and parser.☆156Updated 4 years ago
- Open Dataset of Cobalt Strike Beacon metadata (2018-2022)☆125Updated 3 years ago
- Code for BH21 talk: "Generating YARA Rules by Classifying Malicious Byte Sequences"