u-siem / u-siem-coreLinks
Framework definitions that allow to build a custom SIEM.
☆28Updated last year
Alternatives and similar repositories for u-siem-core
Users that are interested in u-siem-core are comparing it to the libraries listed below
Sorting:
- Cyber threat intelligence crates for Rust☆16Updated last year
- A cross platform forensic parser written in Rust!☆98Updated 2 weeks ago
- A Rust library for parsing and evaluating Sigma rules☆17Updated this week
- Rust bindings for VirusTotal/Yara☆80Updated last week
- A parser for the MFT (Master File Table) format☆150Updated last month
- FIM is an Open Source Host-based file integrity monitoring tool that performs file system analysis, file integrity checking, real time al…☆169Updated last month
- Golang library that implements a sigma log rule parser and match engine.☆102Updated last year
- Rust implementation of the DCSO Bloom filter☆29Updated 4 months ago
- Safe and performant YARA rules evaluator in Rust☆66Updated last week
- Threat hunting with Sysmon and ArangoDB Graphs☆12Updated 5 years ago
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆166Updated last month
- A Go implementation and parser for Sigma rules.☆93Updated 6 months ago
- PAL (Pcap Analysis Library)☆103Updated 4 months ago
- LOKI2 - Simple IOC and YARA Scanner☆106Updated 4 months ago
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆838Updated 2 weeks ago
- A document tagging library☆30Updated 8 months ago
- An implementation of a Windows Event Collector server running on GNU/Linux.☆83Updated last month
- Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.☆323Updated last year
- Owlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact).☆419Updated last year
- Sigma rule specification☆157Updated last week
- ☆225Updated last week
- A Rust library for managing eBPF programs.☆123Updated last year
- SIEGMA - Transform Sigma rules into SIEM consumables☆157Updated 8 months ago
- 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system☆300Updated 6 months ago
- Python library to parse and convert Sigma rules into queries (and whatever else you could imagine)☆500Updated last week
- Curated Windows event log Sigma rules used in Hayabusa and Velociraptor.☆211Updated this week
- Open source endpoint agent providing host information to Zeek. [v2]☆88Updated last month
- The principal objective of this project is to develop a knowledge base of the tactics, techniques, and procedures (TTPs) used by insiders…☆146Updated 4 months ago
- siquery, a Rust osquery implementation to query system information☆59Updated last month
- An opensource sigma conversion tool built using pysigma☆148Updated last month