elastic / endpoint-packageLinks
Repo for developing the endpoint package
☆28Updated this week
Alternatives and similar repositories for endpoint-package
Users that are interested in endpoint-package are comparing it to the libraries listed below
Sorting:
- Elastic Security Documentation☆92Updated last week
- ☆19Updated last year
- EPR package specifications☆19Updated this week
- Elastic Agent - single, unified way to add monitoring for logs, metrics, and other types of data to a host.☆217Updated this week
- ☆41Updated 8 months ago
- Elastic Observability Documentation☆39Updated 2 weeks ago
- ☆312Updated this week
- Malicious Microsoft Office document analyzer☆66Updated last year
- Command line tool used for generating events corpus dynamically given a specific integration☆23Updated 10 months ago
- elastic-package - Command line tool for developing Elastic Integrations☆67Updated last week
- A simple program to hook the current process to identify the manual syscall executions on windows☆263Updated 3 years ago
- Detection Rule License (DRL)☆21Updated 11 months ago
- Package storage for packages served through the package registry service☆10Updated 2 years ago
- Leaky Vessels Dynamic Detector☆103Updated 7 months ago
- ☆36Updated 2 years ago
- Kubernetes offensive framework built in eBPF☆39Updated 2 years ago
- Collection of YARA rules designed for usage through VirusTotal.com.☆79Updated last year
- IOCs for various malware families☆11Updated last year
- Cuckoo Sandbox is an automated dynamic malware analysis system☆10Updated 5 years ago
- Windows Network File System Remote exploit for CVE-2022-30136☆13Updated 2 years ago
- Data to test capa's code and rules.☆46Updated last week
- WMkick is a TCP protocol redirector/MITM tool that targets NTLM authentication message flows in WMI (135/tcp) and Powershell-Remoting/WSM…☆41Updated 4 years ago
- The common parts of the Sysinternals Sysmon tool shared between the Windows and Linux versions.☆65Updated 10 months ago
- Elastic Package Registry (EPR)☆49Updated last week
- Inject unsigned DLL into Protected Process Light (PPL)☆29Updated 7 months ago
- Python library for dissecting and parsing Cobalt Strike related data such as Beacon payloads and Malleable C2 Profiles☆180Updated 5 months ago
- Understand OVAL results in a blink of an eye☆35Updated 3 years ago
- ☆124Updated 3 years ago
- Serverless, real-time, ClamAV+Yara scanning for your S3 Buckets☆32Updated 5 months ago
- Authenticode Hash Calculator for PE32/PE32+ files☆119Updated 5 months ago