u-siem / u-siem-coreLinks
Framework definitions that allow to build a custom SIEM.
☆28Updated last year
Alternatives and similar repositories for u-siem-core
Users that are interested in u-siem-core are comparing it to the libraries listed below
Sorting:
- A cross platform forensic parser written in Rust!☆98Updated 3 weeks ago
- A Rust library for parsing and evaluating Sigma rules☆19Updated 3 weeks ago
- Cyber threat intelligence crates for Rust☆16Updated last year
- A parser for the MFT (Master File Table) format☆150Updated 2 months ago
- Rust bindings for VirusTotal/Yara☆80Updated last month
- A document tagging library☆32Updated 8 months ago
- FIM is an Open Source Host-based file integrity monitoring tool that performs file system analysis, file integrity checking, real time al…☆173Updated last week
- Safe and performant YARA rules evaluator in Rust☆67Updated 3 weeks ago
- LOKI2 - Simple IOC and YARA Scanner☆108Updated 5 months ago
- Owlyshield is an EDR framework designed to safeguard vulnerable applications from potential exploitation (C&C, exfiltration and impact).☆420Updated last year
- Rust implementation of the DCSO Bloom filter☆29Updated 5 months ago
- Golang library that implements a sigma log rule parser and match engine.☆103Updated last year
- A Fast (and safe) parser for the Windows XML Event Log (EVTX) format☆855Updated last week
- A Go implementation and parser for Sigma rules.☆93Updated 7 months ago
- siquery, a Rust osquery implementation to query system information☆59Updated last month
- MalwareDB: bookkeeping for malware, goodware, and unknown files with relationship discovery☆54Updated last week
- A standard for reducing log volume without sacrificing analytical capability☆212Updated 10 months ago
- A Rust library for managing eBPF programs.☆123Updated last year
- Artifact collection tool for *nix systems☆213Updated last year
- Graph platform for Detection and Response☆701Updated 2 years ago
- SOARCA - The Open Source CACAO-based Security Orchestrator!☆100Updated 3 months ago
- Signature engine for all your logs☆173Updated 2 years ago
- Cisco Orbital - Osquery queries by Talos☆135Updated last year
- Chain Reactor is an open source framework for composing executables that simulate adversary behaviors and techniques on Linux endpoints.☆323Updated 8 months ago
- Basically a KrabsETW rip-off written in Rust☆79Updated 2 months ago
- An IDE and translation engine for detection engineers and threat hunters. Be faster, write smarter, keep 100% privacy.☆167Updated 2 weeks ago
- Transform Linux Audit logs for SIEM usage☆805Updated 2 months ago
- ☆225Updated last month
- 🧭 The artifactcollector is a customizable agent to collect forensic artifacts on any Windows, macOS or Linux system☆301Updated 7 months ago
- Kestrel threat hunting language: building reusable, composable, and shareable huntflows across different data sources and threat intel.☆324Updated last year