An implementation of a Windows Event Collector server running on GNU/Linux.
☆95Jan 27, 2026Updated 3 months ago
Alternatives and similar repositories for openwec
Users that are interested in openwec are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Bring Your Own Mitre Att&ck © Matrix !☆13Oct 19, 2023Updated 2 years ago
- a tiny program to consume from ETW providers for research☆56Jan 4, 2025Updated last year
- go client for the wazuh rest api☆13Apr 22, 2026Updated last week
- Private Search Set (PSS) is an extension to standard Bloom filter or a standalone hash file to describe and share private set.☆16Jan 10, 2025Updated last year
- Create dataset for suricata with indicators of MISP instances and add sightings in MISP if an indicator of dataset generates an alert☆37Nov 9, 2022Updated 3 years ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Rustinel is an open-source endpoint detection runtime for Windows and Linux. It collects native telemetry from ETW and eBPF, normalizes e…☆134Apr 25, 2026Updated last week
- ☆59Oct 12, 2024Updated last year
- Knowing which rule should trigger according to the redcannary test☆11Nov 23, 2024Updated last year
- A Rust library for parsing and evaluating Sigma rules☆21Nov 26, 2025Updated 5 months ago
- The home of the SDDLMaker☆29Jan 13, 2025Updated last year
- ☆18Feb 16, 2024Updated 2 years ago
- Transform Linux Audit logs for SIEM usage☆827Apr 17, 2026Updated 2 weeks ago
- Osquery Packs we use for customer security hardening☆12Jun 30, 2025Updated 10 months ago
- http://moaistory.blogspot.com/2018/10/winsearchdbanalyzer.html☆129Jul 20, 2024Updated last year
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- A standalone SIGMA-based detection tool for EVTX, Auditd and Sysmon for Linux logs☆806Apr 6, 2026Updated 3 weeks ago
- The Linux DFIR Collector is a stand-alone collection tool for Gnu / Linux. Dump artifacts in json format with very few impacts on the hos…☆33Mar 9, 2022Updated 4 years ago
- A repository hosting example goodware evtx logs containing sample software installation and basic user interaction☆89Mar 11, 2026Updated last month
- ReWrite of AChoir in Go for Cross Platform forensic artifact collection and processing☆42Apr 18, 2026Updated 2 weeks ago
- Validate if afpacket PACKET_FANOUT_HASH is working properly☆25May 19, 2022Updated 3 years ago
- PowerShell scripts for fast Windows Event Collector configuration with Palantir toolset☆22May 21, 2022Updated 3 years ago
- Set of EVTX samples (>270) mapped to MITRE ATT&CK tactic and techniques to measure your SIEM coverage or developed new use cases.☆626Dec 8, 2025Updated 4 months ago
- ☆38Nov 20, 2025Updated 5 months ago
- pySigma Splunk backend☆42Mar 22, 2026Updated last month
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- Visual Studio Code Microsoft Sysinternal Sysmon configuration file extension.☆54Jul 13, 2023Updated 2 years ago
- simple webapp for converting sigma rules into siem queries using the pySigma library☆50Sep 1, 2023Updated 2 years ago
- Documentation and scripts to properly enable Windows event logs.☆694Oct 3, 2025Updated 7 months ago
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆217Updated this week
- Threat-hunting tool for Linux☆1,057Updated this week
- A home for detection content developed by the delivr.to team☆73Aug 10, 2025Updated 8 months ago
- Cyber threat intelligence crates for Rust☆16Jan 22, 2024Updated 2 years ago
- Repository for Ludus french templates☆24Mar 1, 2026Updated 2 months ago
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆547Apr 21, 2026Updated last week
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- This script and accompanying files will allow system administrators to automatically deploy Microsoft Local Administrator Password Soluti…☆13Aug 18, 2017Updated 8 years ago
- Volatility, on Docker 🐳☆41Nov 20, 2025Updated 5 months ago
- A repo that contains a recursive dump from the ROOT key of every Windows Registry hive (using KAPE) from a vanilla (clean) install of eve…☆52Oct 29, 2025Updated 6 months ago
- Set of Mindmaps providing a detailed overview of the different #Microsoft auditing capacities for Windows, Exchange, Azure,...☆1,092Nov 8, 2025Updated 5 months ago
- server for indexing and querying passive DNS observations☆49Jan 12, 2026Updated 3 months ago
- ☆187Apr 24, 2025Updated last year
- Exploring RPC interfaces on Windows☆351Jan 30, 2024Updated 2 years ago