sysflow-telemetry / sysflow
SysFlow documentation and issues tracker
☆46Updated 6 months ago
Alternatives and similar repositories for sysflow:
Users that are interested in sysflow are comparing it to the libraries listed below
- Red Canary's eBPF Sensor☆103Updated 9 months ago
- A process level network security monitoring and enforcement project for Kubernetes, using eBPF☆43Updated 4 years ago
- A repository to store Rad Fingerprinting data.☆24Updated 8 months ago
- Linux Kernel Runtime Integrity with eBPF☆174Updated last year
- PEACH - a step-by-step framework for modeling and improving SaaS and PaaS tenant isolation, by managing the attack surface exposed by use…☆70Updated 2 years ago
- Yara powered NIDS with high speed packet capture powered by PF_RING☆69Updated 11 months ago
- Open source endpoint agent providing host information to Zeek. [v2]☆80Updated 5 months ago
- Falco rule repository☆117Updated last week
- Osquery Resources☆60Updated 5 years ago
- egrets monitors egress☆45Updated 5 years ago
- SysFlow collection probe☆16Updated 3 months ago
- Tools for conducting analysis of CVE data in Elasticsearch☆74Updated this week
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆70Updated this week
- Mapping NSM rules to MITRE ATT&CK☆70Updated 4 years ago
- Kubernetes offensive framework built in eBPF☆37Updated 2 years ago
- Cisco Orbital - Osquery queries by Talos☆131Updated 7 months ago
- ptrace-based event producer for udig☆67Updated 2 years ago
- Mappings Explorer enables cyber defenders to understand how security controls and capabilities map onto the adversary behaviors catalogue…☆56Updated last week
- Mapping Corelight or Zeek data to Elastic Common Schema fields☆34Updated 2 months ago
- Zeek IDS Dockerfile☆101Updated 2 years ago
- ebpfkit-monitor is a tool that detects and protects against eBPF powered rootkits☆127Updated 2 years ago
- ☆33Updated 3 years ago
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆81Updated last year
- Bro/Zeek integration with osquery☆94Updated 4 years ago
- ☆93Updated 2 months ago
- Convert pcap files into richly-typed ZNG summary logs (Zeek, Suricata, and more)☆80Updated 5 months ago
- K8s API Honeypot with Active Defense Capabilities☆40Updated last year
- Links and resources for the O'Reilly Kubernetes Security book☆98Updated 4 years ago
- SysFlow project APIs☆16Updated 10 months ago
- A repository for OSSEC rules and decoders☆54Updated last year