trailofbits / osquery
SQL powered operating system instrumentation, monitoring, and analytics.
☆37Updated 2 weeks ago
Related projects ⓘ
Alternatives and complementary repositories for osquery
- bareflank based hypervisor with guest support☆59Updated 4 years ago
- The Binary Analysis Metadata tool gathers information about Windows binaries to aid in their analysis. #nsacyber☆156Updated 6 months ago
- A scalable search index for binary files☆116Updated 6 years ago
- SentinelOne's KeRnel Exploits Advanced Mitigations☆52Updated 6 years ago
- Find RSA primes in files☆20Updated 2 years ago
- Data to test capa's code and rules.☆39Updated last week
- A step towards automating the creation of Ghidra processor modules☆36Updated 4 years ago
- X86 disassembler benchmark☆54Updated 4 months ago
- Collection of LLVM passes and triage tools for use with the KRF fuzzer☆35Updated 2 years ago
- ☆27Updated 6 years ago
- Cockroach is your primitive & immortal swiss army knife.☆45Updated 2 years ago
- yara and radare2, better together☆23Updated this week
- Modify ELF executables☆16Updated 5 years ago
- A cross-platform library for verifying Authenticode signatures☆139Updated 3 weeks ago
- Dragodis is a Python framework which allows for the creation of universal disassembler scripts.☆43Updated 5 months ago
- (unofficial) Hyper-V® Development Kit☆215Updated 9 months ago
- PageBuster - dump all executable pages of packed processes.☆201Updated 3 years ago
- Phorklift is an HTTP server and proxy daemon, with clear, powerful and dynamic configuration.☆45Updated 3 years ago
- A sample PoC for container-aware exec events for osquery☆23Updated 9 months ago
- Hashashin: A Fuzzy Matching Tool for Binary Ninja☆88Updated last year
- Dump GNU IFUNC implementation offsets from libc☆10Updated 2 years ago
- Trigram database written in C++, suited for malware indexing☆123Updated last month
- MSR Project Freta☆76Updated 4 months ago
- A proof-of-concept Linux clone of Santa, Google's binary authorization system for macOS☆30Updated 2 years ago
- The current repository contains all the scripts needed to build kernel-mode mac-a-mal malicious activity hooking on macOS.☆82Updated 6 years ago
- Toolset to examine iDevices for Security / Safety Threats☆21Updated last year
- General Research Repository - Only updated when I feel like it☆28Updated last month
- ☆30Updated 6 months ago
- The Manticore User Interface with plugins for Binary Ninja and Ghidra☆73Updated 8 months ago
- suite of binaries used to test function identification☆28Updated 7 years ago