trapmine / trapmine-linux-sensorLinks
An ebpf based agent for monitoring security relevant events on Linux systems.
☆34Updated 2 years ago
Alternatives and similar repositories for trapmine-linux-sensor
Users that are interested in trapmine-linux-sensor are comparing it to the libraries listed below
Sorting:
- Red Canary's eBPF Sensor☆113Updated 7 months ago
- Entropy scanner for Linux to detect packed or encrypted binaries related to malware. Finds malicious files and Linux processes and gives …☆167Updated last year
- Malware Checker Tool generates an HTML report by comparing Hashes, Ip Addresses and URL Addresses through the VirusTotal database.☆36Updated 3 years ago
- enpoint detection / live analysis & sandbox host / signatures quality test☆44Updated 4 years ago
- Sigma Engine implementation in TypeScript☆28Updated 2 years ago
- YaraScanner is a file pattern-matching tool based on YARA rules.☆60Updated 2 years ago
- Rules Shared by the Community from 100 Days of YARA 2023☆78Updated 2 years ago
- ATLAS - Malware Analysis Description☆21Updated 2 years ago
- Factual-rules-generator is an open source project which aims to generate YARA rules about installed software from a machine.☆75Updated 4 years ago
- ☆22Updated 2 years ago
- Linux based vulnerabilities (CVE) exploit detection through runtime security using Falco/Osquery/Yara/Sigma☆21Updated 2 years ago
- log-slapper is an open-source offensive security tool designed for red-team operations as the post-exploit module and assessing your Splu…☆24Updated last year
- Golang Parser for Microsoft Event Logs☆106Updated 3 months ago
- ☆14Updated 5 years ago
- Imphash-like calculation on Golang binaries☆49Updated 3 years ago
- HTTP Headers Hashing (HHHash) is a technique used to create a fingerprint of an HTTP server based on the headers it returns.☆79Updated 2 years ago
- Low budget VirusTotal Intelligence Cosplay☆20Updated 4 years ago
- Linpmem is a linux memory acquisition tool☆95Updated 7 months ago
- ☆33Updated 3 months ago
- VED-eBPF: Kernel Exploit and Rootkit Detection using eBPF☆168Updated last year
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆84Updated last month
- Yara powered NIDS with high speed packet capture powered by PF_RING☆69Updated last year
- ☆90Updated 2 months ago
- ☆19Updated 3 years ago
- Decloak Linux stealth rootkits hiding data with this simple memory mapped IO investigation tool.☆29Updated 4 months ago
- Python based CLI for MalwareBazaar☆39Updated 6 months ago
- ☆10Updated 5 months ago
- Alternative YARA scanning engine☆73Updated 3 years ago
- Lightweight Python-Based Malware Analysis Pipeline☆37Updated last month
- gyp: A pure Go YARA parser☆106Updated last year