bradleyjkemp / sigma-goView external linksLinks
A Go implementation and parser for Sigma rules.
☆95May 15, 2025Updated 9 months ago
Alternatives and similar repositories for sigma-go
Users that are interested in sigma-go are comparing it to the libraries listed below
Sorting:
- Golang library that implements a sigma log rule parser and match engine.☆104Jul 17, 2024Updated last year
- A test case runner for Sigma rules☆14Aug 14, 2024Updated last year
- gyp: A pure Go YARA parser☆106Mar 13, 2024Updated last year
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆527Feb 5, 2026Updated last week
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆412Nov 8, 2025Updated 3 months ago
- JSON schemas for validating CACAO Security Playbooks. Note: In December 2023, Cyentific AS offered and transferred the content of this re…☆19Dec 15, 2023Updated 2 years ago
- Sigma rules from Joe Security☆230Nov 4, 2024Updated last year
- IOK (Indicator Of Kit) is an open source language and ruleset for detecting phishing threat actor tools and tactics☆189Apr 24, 2025Updated 9 months ago
- A Portable Executable parser for Golang☆49Nov 7, 2025Updated 3 months ago
- A Sigma based detection pipeline☆13Dec 15, 2023Updated 2 years ago
- An NTFS file parser in Go☆73Mar 22, 2025Updated 10 months ago
- Storage for the IOCs I collect☆11Mar 26, 2025Updated 10 months ago
- 📚 A collection of tools and libraries to parse filesystems, archives and other data types☆22Oct 20, 2024Updated last year
- ☆51Dec 13, 2025Updated 2 months ago
- 🐻❄️ 🏹 Threat hunting with Polars and flaws.cloud AWS CloudTrail datasets.☆14May 22, 2024Updated last year
- Go implementation of an Extensible Storage Engine parser☆32Feb 15, 2025Updated last year
- Go bindings for YARA☆385Jul 1, 2025Updated 7 months ago
- An open-source command-line tool for cybersecurity reporting automation and a configuration language for reusable templates. Reporting-as…☆67Jul 6, 2025Updated 7 months ago
- This is a repo for fetching Applocker event log by parsing the win-event log☆31Aug 6, 2022Updated 3 years ago
- Threat hunting repo for my independent study on threat hunting with OSQuery☆27Jan 16, 2018Updated 8 years ago
- Publicly shareable windows event log message data☆28Nov 29, 2019Updated 6 years ago
- This package provides an S3 implementation for Go1.16 filesystem interface.☆13Apr 21, 2025Updated 9 months ago
- 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system☆305May 7, 2025Updated 9 months ago
- Python3 script which decrypts files encrypted by flawed Cl0p ELF variant.☆17Feb 6, 2023Updated 3 years ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆53Jul 27, 2022Updated 3 years ago
- YARA rule analyzer to improve rule quality and performance☆111Jan 18, 2026Updated 3 weeks ago
- Firepit - STIX Columnar Storage☆17Jun 5, 2024Updated last year
- Legacy Sigma Tools (sigmac etc.)☆15May 7, 2023Updated 2 years ago
- stix-icons is a collection of colourful and clean icons for use in software, training and marketing material to visualize cyber threats a…☆37Dec 15, 2022Updated 3 years ago
- Convert Sigma rules to SIEM queries, directly in your browser.☆110Jan 24, 2026Updated 3 weeks ago
- PyVelociraptor contains the python bindings for the Velociraptor API.☆21Updated this week
- Detecting Cobalt Strike Team Servers on targets through traffic telemetry.☆22Aug 13, 2024Updated last year
- ☆170Nov 11, 2022Updated 3 years ago
- Sigma rule specification☆172Feb 5, 2026Updated last week
- VSCode extension for the YARA pattern matching language☆63Jan 10, 2024Updated 2 years ago
- A Python package and command line utility for scanning emails with YARA rules☆21Jan 23, 2026Updated 3 weeks ago
- Rules generated from our investigations.☆204Jun 17, 2025Updated 7 months ago
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆780Updated this week
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆613Dec 8, 2025Updated 2 months ago