An implementation of a Windows Event Collector server running on GNU/Linux.
☆96Jan 27, 2026Updated 4 months ago
Alternatives and similar repositories for openwec
Users that are interested in openwec are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Bring Your Own Mitre Att&ck © Matrix !☆13Oct 19, 2023Updated 2 years ago
- a tiny program to consume from ETW providers for research☆55Jan 4, 2025Updated last year
- Private Search Set (PSS) is an extension to standard Bloom filter or a standalone hash file to describe and share private set.☆16Jan 10, 2025Updated last year
- ☆58Oct 12, 2024Updated last year
- Knowing which rule should trigger according to the redcannary test☆11Nov 23, 2024Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A Rust library for parsing and evaluating Sigma rules☆22Nov 26, 2025Updated 6 months ago
- The home of the SDDLMaker☆29Jan 13, 2025Updated last year
- ☆18Feb 16, 2024Updated 2 years ago
- Transform Linux Audit logs for SIEM usage☆829Updated this week
- Osquery Packs we use for customer security hardening☆12Jun 30, 2025Updated 10 months ago
- http://moaistory.blogspot.com/2018/10/winsearchdbanalyzer.html☆132Jul 20, 2024Updated last year
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆812May 15, 2026Updated last week
- Open-source endpoint detection engine for Windows and Linux using ETW, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.☆307May 18, 2026Updated last week
- The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the hos…☆32Updated this week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆89Mar 11, 2026Updated 2 months ago
- ReWrite of AChoir in Go for Cross Platform forensic artifact collection and processing☆42May 18, 2026Updated last week
- Validate if afpacket PACKET_FANOUT_HASH is working properly☆25May 19, 2022Updated 4 years ago
- PowerShell scripts for fast Windows Event Collector configuration with Palantir toolset☆22May 21, 2022Updated 4 years ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆629Updated this week
- Burp Suite Pro extension☆11May 26, 2017Updated 9 years ago
- ☆38Nov 20, 2025Updated 6 months ago
- pySigma Splunk backend☆43Mar 22, 2026Updated 2 months ago
- Threat feeds designed to extract adversarial TTPs and IOCs, using: ✨AI✨☆72Updated this week
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- 分析ツール結果シート☆18Nov 13, 2017Updated 8 years ago
- Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.☆54Jul 13, 2023Updated 2 years ago
- IR drill plateform☆24Jul 29, 2025Updated 9 months ago
- simple webapp for converting sigma rules into siem queries using the pySigma library☆50Sep 1, 2023Updated 2 years ago
- Repository to provide files related to our blog articles.☆16May 26, 2025Updated last year
- Documentation and scripts to properly enable Windows event logs.☆704Oct 3, 2025Updated 7 months ago
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆218May 3, 2026Updated 3 weeks ago
- Threat-hunting tool for Linux☆1,067Updated this week
- A home for detection content developed by the delivr.to team☆73Aug 10, 2025Updated 9 months ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Cyber threat intelligence crates for Rust☆16Jan 22, 2024Updated 2 years ago
- Fluentd plugin to route records based on Kubernetes labels and namespace☆13Apr 11, 2025Updated last year
- Repository for Ludus french templates☆24Mar 1, 2026Updated 2 months ago
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆556May 10, 2026Updated 2 weeks ago
- This script and accompanying files will allow system administrators to automatically deploy Microsoft Local Administrator Password Soluti…☆13Aug 18, 2017Updated 8 years ago
- Volatility, on Docker 🐳☆41Nov 20, 2025Updated 6 months ago
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆52Oct 29, 2025Updated 6 months ago