sysflow-telemetry / sysflow
SysFlow documentation and issues tracker
☆46Updated 4 months ago
Alternatives and similar repositories for sysflow:
Users that are interested in sysflow are comparing it to the libraries listed below
- A process level network security monitoring and enforcement project for Kubernetes, using eBPF☆42Updated 4 years ago
- Red Canary's eBPF Sensor☆101Updated 6 months ago
- egrets monitors egress☆46Updated 4 years ago
- Osquery Resources☆60Updated 5 years ago
- Yara powered NIDS with high speed packet capture powered by PF_RING☆67Updated 8 months ago
- SysFlow collection probe☆16Updated 3 weeks ago
- Falco rule repository☆105Updated this week
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆66Updated 2 weeks ago
- Wireshark plugin to display Suricata analysis info☆93Updated 3 years ago
- Tools for conducting analysis of CVE data in Elasticsearch☆74Updated 6 months ago
- Cisco Orbital - Osquery queries by Talos☆129Updated 5 months ago
- A repository to store Rad Fingerprinting data.☆23Updated 5 months ago
- Suricata Verification Tests - Testing Suricata Output☆104Updated this week
- Linux Kernel Runtime Integrity with eBPF☆172Updated last year
- PEACH - a step-by-step framework for modeling and improving SaaS and PaaS tenant isolation, by managing the attack surface exposed by use…☆67Updated 2 years ago
- Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)☆79Updated 3 months ago
- ptrace-based event producer for udig☆67Updated 2 years ago
- ☆33Updated 3 years ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆65Updated this week
- Falco plugins registry☆87Updated this week
- K8s API Honeypot with Active Defense Capabilities☆40Updated last year
- SysFlow project APIs☆15Updated 7 months ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 months ago
- VINCE is the Vulnerability Information and Coordination Environment developed and used by the CERT Coordination Center to improve coordin…☆60Updated last month
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆80Updated last year
- simple YARA-based IOC scanner☆165Updated 3 weeks ago
- Understand OVAL results in a blink of an eye☆35Updated 2 years ago
- fast, extensible, versatile event router for Suricata's EVE-JSON format☆51Updated 6 months ago
- ☆85Updated 6 months ago
- SysFlow edge processing pipeline☆14Updated 2 weeks ago