sysflow-telemetry / sf-processor
SysFlow edge processing pipeline
☆14Updated 3 months ago
Related projects ⓘ
Alternatives and complementary repositories for sf-processor
- SysFlow collection probe☆15Updated last week
- Red Canary's eBPF Sensor☆101Updated 4 months ago
- Automated testing, generation & manipulation of #osquery packs☆70Updated last month
- Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.☆300Updated last month
- SysFlow documentation and issues tracker☆45Updated last month
- ☆16Updated 6 months ago
- 🐝 BPFBox 📦 Exploring process confinement in eBPF☆101Updated 10 months ago
- Posture Attribute Collection and Evaluation☆23Updated last year
- OpenVEX Specification☆132Updated 4 months ago
- Elastic's eBPF☆67Updated this week
- A process level network security monitoring and enforcement project for Kubernetes, using eBPF☆40Updated 4 years ago
- Automated build and mirror of eBPF kernel probes for use as a driver with the Falco runtime security agent (https://falco.org/)☆16Updated this week
- Falco rule repository☆96Updated last month
- ptrace-based event producer for udig☆67Updated 2 years ago
- vexctl is a tool to attest VEX impact statements☆44Updated last year
- K8s API Honeypot with Active Defense Capabilities☆39Updated 10 months ago
- A Go implementation and parser for Sigma rules.☆84Updated 2 months ago
- A Software as a Service (SaaS) log collection framework.☆131Updated last month
- OCI hook to trace syscalls and generate a seccomp profile☆303Updated last week
- This repo contains example of raw event examples and possible translations to the OCSF schema.☆33Updated 2 weeks ago
- ☆101Updated last month
- Linux Kernel Runtime Integrity with eBPF☆164Updated last year
- Kit for building Falco drivers: kernel modules or eBPF probes☆64Updated this week
- ebpfpub is a generic function tracing library for Linux that supports tracepoints, kprobes and uprobes.☆113Updated last year
- Cryptography Bill of Materials☆58Updated 2 months ago
- ☆37Updated 2 months ago
- Technical Advisory Council☆109Updated last week
- Generate a variety of suspect actions that are detected by Falco rulesets☆94Updated this week