u-siem / u-siem-core
Framework definitions that allow to build a custom SIEM.
☆25Updated 6 months ago
Alternatives and similar repositories for u-siem-core:
Users that are interested in u-siem-core are comparing it to the libraries listed below
- A cross platform forensic parser written in Rust!☆80Updated this week
- A document tagging library☆29Updated this week
- Cyber threat intelligence crates for Rust☆13Updated last year
- Convert Sigma Rules to different formats☆11Updated 7 months ago
- A forensic evidence acquirer☆86Updated 3 years ago
- Rust bindings for VirusTotal/Yara☆75Updated 3 weeks ago
- A parser for the MFT (Master File Table) format☆136Updated last year
- LOKI2 - Simple IOC and YARA Scanner☆87Updated 8 months ago
- MalwareDB: bookkeeping for malware, goodware, and unknown files with relationship discovery☆41Updated last week
- Cisco Orbital - Osquery queries by Talos☆130Updated 7 months ago
- Safe and performant YARA rules evaluator in Rust☆46Updated last week
- Signature engine for all your logs☆166Updated last year
- Forensic framework to build tools that can be reused in multiple projects without changing anything☆26Updated 3 weeks ago
- Rust implementation of the DCSO Bloom filter☆27Updated 6 months ago
- Artifact collection tool for *nix systems☆202Updated last year
- Threat hunting with Sysmon and ArangoDB Graphs☆11Updated 4 years ago
- Indicators of compromise, YARA rules, and Python scripts to supplement the SANS CTI Summit 2021 talk: "xStart when you're ready".☆14Updated 3 years ago
- 🕵️♀️ Find, locate, and query files for ops and security experts ⚡️⚡️⚡️☆33Updated 2 years ago
- SIEGMA - Transform Sigma rules into SIEM consumables☆149Updated 2 weeks ago
- A CALDERA plugin☆75Updated 2 weeks ago
- siquery, a Rust osquery implementation to query system information☆58Updated 2 years ago
- An opensource sigma conversion tool built using pysigma☆121Updated 3 months ago
- Golang library that implements a sigma log rule parser and match engine.☆94Updated 8 months ago
- This crate provides functions for working with IPv4 CIDRs and IPv6 CIDRs.☆32Updated last year
- Security Aware Wire Protocol parsing library☆38Updated 5 months ago
- A Windows registry file parser written in Rust☆37Updated last year
- Sigma Detection Rule Repository☆87Updated 4 years ago
- FIM is an Open Source Host-based file integrity monitoring tool that performs file system analysis, file integrity checking, real time al…☆155Updated last week
- A Rust library for managing eBPF programs.☆117Updated last year
- Basically a KrabsETW rip-off written in Rust☆66Updated 7 months ago