A Go implementation and parser for Sigma rules.
☆99May 15, 2025Updated last year
Alternatives and similar repositories for sigma-go
Users that are interested in sigma-go are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Golang library that implements a sigma log rule parser and match engine.☆105Jul 17, 2024Updated last year
- A test case runner for Sigma rules☆14Aug 14, 2024Updated last year
- gyp: A pure Go YARA parser☆107Mar 13, 2024Updated 2 years ago
- A Sigma based detection pipeline☆12Dec 15, 2023Updated 2 years ago
- 📚 A collection of tools and libraries to parse filesystems, archives and other data types☆22Oct 20, 2024Updated last year
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Go implementation of an Extensible Storage Engine parser☆32May 25, 2026Updated 3 weeks ago
- ☆57Dec 13, 2025Updated 6 months ago
- kaitaigo is a compiler and runtime to create Go parsers from Kaitai Struct files☆18Apr 20, 2022Updated 4 years ago
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆566Updated this week
- Set of SIGMA rules (>350) mapped to MITRE ATT&CK tactic and techniques☆435May 21, 2026Updated 3 weeks ago
- An NTFS file parser in Go☆76Mar 31, 2026Updated 2 months ago
- JSON schemas for validating CACAO Security Playbooks. Note: In December 2023, Cyentific AS offered and transferred the content of this re…☆19Dec 15, 2023Updated 2 years ago
- This package provides an S3 implementation for Go1.16 filesystem interface.☆13Apr 8, 2026Updated 2 months ago
- Threat hunting repo for my independent study on threat hunting with OSQuery☆27Jan 16, 2018Updated 8 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Storage for the IOCs I collect☆11Apr 3, 2026Updated 2 months ago
- DFF (Digital Forensics Framework)☆11Jan 6, 2021Updated 5 years ago
- IOK (Indicator Of Kit) is an open source language and ruleset for detecting phishing threat actor tools and tactics☆193Apr 24, 2025Updated last year
- A Portable Executable parser for Golang☆46Nov 7, 2025Updated 7 months ago
- Go bindings for YARA☆388Jul 1, 2025Updated 11 months ago
- Ansible playbook to convert Sigma rules to ElastAlert rules☆10Feb 5, 2021Updated 5 years ago
- Golang io/fs implementation for Google Cloud Storage☆13Jan 20, 2024Updated 2 years ago
- 🐻❄️ 🏹 Threat hunting with Polars and flaws.cloud AWS CloudTrail datasets.☆14May 22, 2024Updated 2 years ago
- Package ghfs wraps the github v3 rest api with io/fs.☆10Aug 23, 2022Updated 3 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Threat Detection & Anomaly Detection rules for popular open-source components☆53Jul 27, 2022Updated 3 years ago
- Sigma rules from Joe Security☆241Nov 4, 2024Updated last year
- A linter for ksy files.☆11Aug 15, 2021Updated 4 years ago
- A source-available command-line tool for cybersecurity reporting☆71Updated this week
- API for parsing binary files using a predefined grammar☆15Nov 17, 2016Updated 9 years ago
- pySigma Cookiecutter backend template☆25Sep 17, 2025Updated 9 months ago
- Convert Sigma rules to SIEM queries, directly in your browser.☆116Jun 6, 2026Updated last week
- YARA rule analyzer to improve rule quality and performance☆115Jun 4, 2026Updated 2 weeks ago
- A Python package and command line utility for scanning emails with YARA rules☆23May 24, 2026Updated 3 weeks ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- PyVelociraptor contains the python bindings for the Velociraptor API.☆23May 5, 2026Updated last month
- Publicly shareable windows event log message data☆29Nov 29, 2019Updated 6 years ago
- 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system☆308May 7, 2025Updated last year
- Kaitai Struct YAML (KSY) schema specification☆15Sep 12, 2025Updated 9 months ago
- Import specific data sources into the Sigma generic and open signature format.☆79May 6, 2022Updated 4 years ago
- Sigma rule specification☆195Jun 9, 2026Updated last week
- ☆172Nov 11, 2022Updated 3 years ago