sysflow-telemetry / sf-processor
SysFlow edge processing pipeline
☆14Updated 2 weeks ago
Alternatives and similar repositories for sf-processor:
Users that are interested in sf-processor are comparing it to the libraries listed below
- SysFlow collection probe☆16Updated 3 weeks ago
- Red Canary's eBPF Sensor☆101Updated 6 months ago
- SysFlow documentation and issues tracker☆46Updated 4 months ago
- Falco rule repository☆105Updated this week
- Automated testing, generation & manipulation of #osquery packs☆72Updated 3 months ago
- A process level network security monitoring and enforcement project for Kubernetes, using eBPF☆42Updated 4 years ago
- 🐝 Ransomware Detection using Machine Learning with eBPF for Linux.☆58Updated 2 months ago
- ☆39Updated 2 weeks ago
- OpenVEX Specification☆140Updated 6 months ago
- ☆16Updated 8 months ago
- 🐝 BPFBox 📦 Exploring process confinement in eBPF☆101Updated last year
- Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.☆305Updated 4 months ago
- ptrace-based event producer for udig☆67Updated 2 years ago
- Process behaviour anomaly detection using eBPF and unsupervised-learning Autoencoders☆130Updated 2 years ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated this week
- Generate a variety of suspect actions that are detected by Falco rulesets☆101Updated this week
- ☆16Updated last year
- agent for handling seccomp descriptors for container runtimes☆44Updated 11 months ago
- Automated build and mirror of eBPF kernel probes for use as a driver with the Falco runtime security agent (https://falco.org/)☆16Updated 2 months ago
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆115Updated last year
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- egrets monitors egress☆46Updated 4 years ago
- Posture Attribute Collection and Evaluation☆24Updated last year
- libsinsp, libscap, the kernel module driver, and the eBPF driver sources☆247Updated this week
- K8s API Honeypot with Active Defense Capabilities☆40Updated last year
- This repo contains example of raw event examples and possible translations to the OCSF schema.☆35Updated this week
- Augmentation to Machine Readable CTI☆27Updated last month
- PEACH - a step-by-step framework for modeling and improving SaaS and PaaS tenant isolation, by managing the attack surface exposed by use…☆67Updated 2 years ago
- OASIS TC Open Repository: A GitHub public repository for development of a python library to transform between data-interchange formats (s…☆11Updated 2 years ago
- A standard API specification for exchanging supply chain artifacts and intelligence☆68Updated last month