sysflow-telemetry / sysflowLinks
SysFlow documentation and issues tracker
☆45Updated last year
Alternatives and similar repositories for sysflow
Users that are interested in sysflow are comparing it to the libraries listed below
Sorting:
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆79Updated 3 months ago
- Red Canary's eBPF Sensor☆109Updated 3 months ago
- Yara powered NIDS with high speed packet capture powered by PF_RING☆69Updated last year
- A process level network security monitoring and enforcement project for Kubernetes, using eBPF☆44Updated 5 years ago
- Falco rule repository☆136Updated this week
- A repository to store Rad Fingerprinting data.☆24Updated last year
- A repository for OSSEC rules and decoders☆55Updated 2 years ago
- Kit for building Falco drivers: kernel modules or eBPF probes☆67Updated this week
- Tools for conducting analysis of CVE data in Elasticsearch☆75Updated 2 months ago
- Linux Kernel Runtime Integrity with eBPF☆183Updated last year
- Generate a variety of suspect actions that are detected by Falco rulesets☆108Updated 4 months ago
- Osquery Resources☆62Updated 6 years ago
- Open source endpoint agent providing host information to Zeek. [v2]☆86Updated 3 weeks ago
- Cisco Orbital - Osquery queries by Talos☆135Updated last year
- Suricata Verification Tests - Testing Suricata Output☆116Updated last week
- Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)☆88Updated 5 months ago
- Wireshark plugin to display Suricata analysis info☆95Updated 3 years ago
- Elastic's eBPF☆69Updated last week
- PEACH - a step-by-step framework for modeling and improving SaaS and PaaS tenant isolation, by managing the attack surface exposed by use…☆72Updated 2 years ago
- This project is no longer maintained. There's a successor at https://github.com/zeek/zeek-agent-v2☆123Updated 4 years ago
- Links and resources for the O'Reilly Kubernetes Security book☆99Updated 4 years ago
- ptrace-based event producer for udig☆67Updated 3 years ago
- Build a local copy of CPE(Common Platform Enumeration)☆106Updated last week
- bpflock - eBPF driven security for locking and auditing Linux machines☆150Updated 3 years ago
- egrets monitors egress☆46Updated 5 years ago
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 3 weeks ago
- Container Blackbox Security Auditing Tool: enumerates security configuration from within the target container☆105Updated 6 years ago
- Provide a shell like interface by utilizing osquery's distributed API☆81Updated 5 years ago
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆184Updated last year
- A POC for DNS spoofing in kubernetes clusters. Runs with minimum capabilities, on default installations of kuberentes.☆78Updated 6 years ago