A Go implementation and parser for Sigma rules.
☆95May 15, 2025Updated 9 months ago
Alternatives and similar repositories for sigma-go
Users that are interested in sigma-go are comparing it to the libraries listed below
Sorting:
- Golang library that implements a sigma log rule parser and match engine.☆105Jul 17, 2024Updated last year
- A test case runner for Sigma rules☆14Aug 14, 2024Updated last year
- gyp: A pure Go YARA parser☆107Mar 13, 2024Updated last year
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆534Feb 15, 2026Updated 3 weeks ago
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆414Nov 8, 2025Updated 4 months ago
- kaitaigo is a compiler and runtime to create Go parsers from Kaitai Struct files☆18Apr 20, 2022Updated 3 years ago
- JSON schemas for validating CACAO Security Playbooks. Note: In December 2023, Cyentific AS offered and transferred the content of this re…☆19Dec 15, 2023Updated 2 years ago
- Sigma rules from Joe Security☆233Nov 4, 2024Updated last year
- IOK (Indicator Of Kit) is an open source language and ruleset for detecting phishing threat actor tools and tactics☆189Apr 24, 2025Updated 10 months ago
- A Portable Executable parser for Golang☆48Nov 7, 2025Updated 4 months ago
- A Sigma based detection pipeline☆12Dec 15, 2023Updated 2 years ago
- An NTFS file parser in Go☆72Mar 22, 2025Updated 11 months ago
- Storage for the IOCs I collect☆11Mar 26, 2025Updated 11 months ago
- 📚 A collection of tools and libraries to parse filesystems, archives and other data types☆22Oct 20, 2024Updated last year
- ☆52Dec 13, 2025Updated 2 months ago
- 🐻❄️ 🏹 Threat hunting with Polars and flaws.cloud AWS CloudTrail datasets.☆14May 22, 2024Updated last year
- Go implementation of an Extensible Storage Engine parser☆32Feb 15, 2025Updated last year
- Go bindings for YARA☆387Jul 1, 2025Updated 8 months ago
- An open-source command-line tool for cybersecurity reporting automation and a configuration language for reusable templates. Reporting-as…☆67Jul 6, 2025Updated 8 months ago
- Threat hunting repo for my independent study on threat hunting with OSQuery☆27Jan 16, 2018Updated 8 years ago
- Publicly shareable windows event log message data☆28Nov 29, 2019Updated 6 years ago
- This package provides an S3 implementation for Go1.16 filesystem interface.☆13Updated this week
- 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system☆306May 7, 2025Updated 10 months ago
- Python3 script which decrypts files encrypted by flawed Cl0p ELF variant.☆17Feb 6, 2023Updated 3 years ago
- Threat Detection & Anomaly Detection rules for popular open-source components☆53Jul 27, 2022Updated 3 years ago
- YARA rule analyzer to improve rule quality and performance☆113Jan 18, 2026Updated last month
- Import specific data sources into the Sigma generic and open signature format.☆79May 6, 2022Updated 3 years ago
- Firepit - STIX Columnar Storage☆18Jun 5, 2024Updated last year
- Legacy Sigma Tools (sigmac etc.)☆16May 7, 2023Updated 2 years ago
- Convert Sigma rules to SIEM queries, directly in your browser.☆111Jan 24, 2026Updated last month
- stix-icons is a collection of colourful and clean icons for use in software, training and marketing material to visualize cyber threats a…☆38Dec 15, 2022Updated 3 years ago
- PyVelociraptor contains the python bindings for the Velociraptor API.☆21Feb 11, 2026Updated 3 weeks ago
- Detecting Cobalt Strike Team Servers on targets through traffic telemetry.☆22Aug 13, 2024Updated last year
- ☆171Nov 11, 2022Updated 3 years ago
- Sigma rule specification☆172Feb 5, 2026Updated last month
- Provide a shell like interface by utilizing osquery's distributed API☆82Jun 24, 2020Updated 5 years ago
- VSCode extension for the YARA pattern matching language☆63Jan 10, 2024Updated 2 years ago
- A Python package and command line utility for scanning emails with YARA rules☆21Jan 23, 2026Updated last month
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆786Feb 22, 2026Updated 2 weeks ago