HIDS全称是Host-based Intrusion Detection System,即基于主机型入侵检测系统,HIDS运行依赖这样一个原理:一个成功的入侵者一般而言都会留下他们入侵的痕迹。本人更倾向于通过记录主机的重要信息变更来发现入侵者。 本项目由两部分组成:一部分osquery、另一部分监控脚本来补充osquery规则的不足; 本文是第一部分osquery规则部分,实现绝大部分主机信息监控。
☆107Dec 29, 2017Updated 8 years ago
Alternatives and similar repositories for HIDS
Users that are interested in HIDS are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 以甲方安全人员的视角,尽可能收集发现企业的域名和服务器公网IP资产☆65Dec 15, 2017Updated 8 years ago
- By Kprobe technology Open Source Host-based Intrusion Detection System(HIDS), from E_Bwill.☆602Apr 1, 2021Updated 4 years ago
- [archived] 一款实验性质的主机入侵检测系统☆2,190Jun 29, 2020Updated 5 years ago
- 针对大量WEB资产进行分布式WEB安全扫描,发现web环境下常规的一些安全漏洞☆99Apr 19, 2019Updated 6 years ago
- WAF测试工具---用例测试(增加result输出)☆13Mar 6, 2015Updated 11 years ago
- ipstatistics is a script based on the ipip library that is used to quickly filter the ip list.☆14Aug 21, 2020Updated 5 years ago
- SDL China☆33Nov 8, 2018Updated 7 years ago
- 本程序旨在为安全应急响应人员对Linux主机排查时提供便利,实现主机侧Checklist的自动全面化检测,根据检测结果自动数据聚合,进行黑客攻击路径溯源。☆2,808Aug 7, 2022Updated 3 years ago
- 主机入侵检测系统(HIDS)☆31Feb 28, 2018Updated 8 years ago
- Open-Source Security Architecture | 开源安全架构☆943May 10, 2021Updated 4 years ago
- 自动化被动扫描系统分为数据源、数据处理、漏洞验证等三个子系统,本系统属于漏洞验证部分,根据提供的数据进行分布式安全验证,确定是否包含相关严重漏洞。☆49Dec 26, 2017Updated 8 years ago
- 超精简的POC扫描框架☆10Aug 5, 2019Updated 6 years ago
- Network Security Vulnerability Scanner☆115May 15, 2023Updated 2 years ago
- 护网杯 2018 WEB (1) easy_tornado☆15Aug 22, 2019Updated 6 years ago
- 一个HIDS agent端的demo☆17Feb 29, 2020Updated 6 years ago
- 测评工具☆308Mar 25, 2021Updated 4 years ago
- 洞察-宜信集应用系统资产管理、漏洞全生命周期管理、安全知识库管理三位一体的平台。☆1,181Jan 12, 2021Updated 5 years ago
- 基于 Docker 的真实应用测试环境☆262Aug 14, 2023Updated 2 years ago
- Suricata IDS rules 用来检测红队渗透/恶意行为等,支持检测CobaltStrike/MSF/Empire/DNS隧道/Weevely/菜刀/冰蝎/挖矿/反弹shell/ICMP隧道等☆1,266Jul 8, 2023Updated 2 years ago
- CloudWalker Platform☆676Dec 14, 2022Updated 3 years ago
- 本脚本是HIDS组成的一部分,旨在对指定监控目录进行文件hash记录,定时运行,发现文件替换、修改等后门可疑程序。☆13Dec 15, 2017Updated 8 years ago
- Elkeid is an open source solution that can meet the security requirements of various workloads such as hosts, containers and K8s, and ser…☆2,609Mar 9, 2026Updated 2 weeks ago
- Hades is a Host-Based Intrusion Detection System based on eBPF(mainly)☆305Nov 30, 2024Updated last year
- MOSEC-X-PLUGIN 后端API服务☆24Aug 11, 2020Updated 5 years ago
- 对公网IP列表进行端口服务扫描,发现周期内的端口服务变化情况和弱口令安全风险☆609Apr 12, 2021Updated 4 years ago
- Webshell扫描工具,通过各种规则和算法实现服务器脚本后门查杀☆121Aug 22, 2016Updated 9 years ago
- weblog/dnslog平台 Docker容器化部署☆36Jan 12, 2022Updated 4 years ago
- CTF学习交流入群题 Web 20180626☆24Sep 28, 2019Updated 6 years ago
- Linux 入侵检测脚本☆17Mar 20, 2021Updated 5 years ago
- 合规审计平台☆472Mar 23, 2022Updated 4 years ago
- 等级保护安全加固方案☆30Apr 18, 2019Updated 6 years ago
- 通用的POC检测框架,有足够的POC,就可以找出相应的漏洞☆45Apr 27, 2016Updated 9 years ago
- suricata IDS的规则,测试在用的,部分自写的规则视情况放出。☆18Apr 16, 2019Updated 6 years ago
- 针对数据库的敏感数据检测脚本:扫描库、schema级别的表或视图的数据,发现其中的敏感字段。敏感类型包括姓名、电话、身份证号、电子邮箱、地址、银行账号。☆38Mar 16, 2018Updated 8 years ago
- 甲方安全工程师必备,内部钓鱼系统☆230Jan 15, 2022Updated 4 years ago
- Linux命令转发记录☆62Jul 15, 2019Updated 6 years ago
- ☆10Sep 24, 2025Updated 6 months ago
- GitHub 泄露监控系统(GitHub Sensitive Information Leakage Monitor Spider)☆2,036May 21, 2022Updated 3 years ago
- 红队基础设施自动化部署工具☆852Jan 4, 2023Updated 3 years ago