u-siem / u-siem-coreLinks
Framework definitions that allow to build a custom SIEM.
☆28Updated last year
Alternatives and similar repositories for u-siem-core
Users that are interested in u-siem-core are comparing it to the libraries listed below
Sorting:
- A Rust library for parsing and evaluating Sigma rules☆19Updated last month
- A cross platform forensic parser written in Rust!☆99Updated this week
- Cyber threat intelligence crates for Rust☆16Updated last year
- Rust bindings for VirusTotal/Yara☆80Updated last month
- Rust implementation of the DCSO Bloom filter☆29Updated 5 months ago
- FIM is an Open Source Host-based file integrity monitoring tool that performs file system analysis, file integrity checking, real time al…☆173Updated last week
- Golang library that implements a sigma log rule parser and match engine.☆103Updated last year
- A parser for the MFT (Master File Table) format☆155Updated last week
- Safe and performant YARA rules evaluator in Rust☆67Updated last month
- A Go implementation and parser for Sigma rules.☆93Updated 7 months ago
- Signature engine for all your logs☆173Updated 2 years ago
- A document tagging library☆32Updated 9 months ago
- A Rust library for managing eBPF programs.☆123Updated last year
- Artifact collection tool for *nix systems☆212Updated last year
- An implementation of a Windows Event Collector server running on GNU/Linux.☆88Updated 2 weeks ago
- An open standard for hashing network flows into identifiers, a.k.a "Community IDs".☆192Updated last year
- SIEGMA - Transform Sigma rules into SIEM consumables☆157Updated 10 months ago
- Security Aware Wire Protocol parsing library☆40Updated last year
- Sigma Detection Rule Repository☆92Updated 5 years ago
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆168Updated last month
- MalwareDB: bookkeeping for malware, goodware, and unknown files with relationship discovery☆54Updated this week
- Suricata Language Server is an implementation of the Language Server Protocol for Suricata signatures. It adds syntax check, hints and au…☆84Updated 2 weeks ago
- simple YARA-based IOC scanner☆173Updated last month
- Cisco Orbital - Osquery queries by Talos☆136Updated last year
- Threat hunting with Sysmon and ArangoDB Graphs☆12Updated 5 years ago
- PAL (Pcap Analysis Library)☆104Updated 5 months ago
- A CALDERA plugin☆79Updated 2 months ago
- 🐍 High-performance, multi-threaded YARA & IOC scanner☆190Updated this week
- Owlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact).☆420Updated last year
- Open source endpoint agent providing host information to Zeek. [v2]☆90Updated last month